nakkan13
2018-07-08, 21:35
Hello,
Thank you for the help I am lost and sad.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by hometown (administrator) on DESKTOP-VTV5VMP (08-07-2018 10:26:18)
Running from C:\Users\hometown\Desktop
Loaded Profiles: hometown (Available Profiles: hometown)
Platform: Windows 10 Pro Version 1803 17134.137 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64gh4811.inf_amd64_f02d96a3e7a6ed57\IntelCpHDCPSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64gh4811.inf_amd64_f02d96a3e7a6ed57\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\SurfaceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Windows\System32\SurfaceDTX.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.136_none_eb1580521d543895\TiWorker.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [SurfaceDTX.exe] => C:\Windows\System32\SurfaceDTX.exe [804744 2017-11-01] ()
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4144944 2013-02-14] (ESET)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{7111250b-1515-4e75-928c-6e3c5d4171a3}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
StartMenuInternet: IEXPLORE.EXE -
FireFox:
========
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: (ESET Endpoint Security Extension) - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2018-07-07] [Legacy] [not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-07] (Google Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Profile: C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default [2018-07-08]
CHR Extension: (Slides) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-07]
CHR Extension: (Docs) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-07]
CHR Extension: (Google Drive) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-07]
CHR Extension: (DuckDuckGo) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2018-07-07]
CHR Extension: (YouTube) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-07]
CHR Extension: (Sheets) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-07]
CHR Extension: (Google Docs Offline) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-07]
CHR Extension: (Gmail) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-07]
CHR Extension: (Chrome Media Router) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [40888 2013-02-14] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1020304 2013-02-14] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [190208 2013-02-14] (ESET)
S2 IntelAudioService; C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe [161880 2017-10-03] (Intel)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S2 SurfaceDtxService; C:\Windows\system32\SurfaceDtxService.exe [91016 2017-11-01] (Microsoft Corporation)
S2 SurfaceUsbHubFwUpdateService; C:\Windows\System32\SurfaceUsbHubFwUpdateService.exe [942360 2016-12-06] (Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-07-06] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-07-06] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [217000 2013-02-04] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [183016 2013-04-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [153200 2013-02-04] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [141304 2013-02-04] (ESET)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvmso.inf_amd64_b89aa41766002e30\nvlddmkm.sys [16925296 2017-10-31] (NVIDIA Corporation)
S3 smbdirect; C:\Windows\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
S3 SurfaceBaseIntegration; C:\Windows\System32\drivers\SurfaceBaseIntegration.sys [68144 2016-04-11] (Microsoft Corporation)
R0 SurfaceUsbHubFwUpdate; C:\Windows\System32\drivers\SurfaceUsbHubFwUpdate.sys [71448 2016-12-06] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46592 2018-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [340008 2018-07-06] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59944 2018-07-06] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-08 10:26 - 2018-07-08 10:26 - 000011415 _____ C:\Users\hometown\Desktop\FRST.txt
2018-07-08 10:14 - 2018-07-08 10:26 - 000000000 ____D C:\FRST
2018-07-08 10:13 - 2018-07-08 10:13 - 002412544 _____ (Farbar) C:\Users\hometown\Desktop\FRST64.exe
2018-07-08 10:11 - 2018-07-08 10:11 - 000003788 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2018-07-08 10:11 - 2018-07-08 10:11 - 000002236 _____ C:\Users\hometown\Desktop\Tweaking.com - Windows Repair.lnk
2018-07-08 10:11 - 2018-07-08 10:11 - 000000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-VTV5VMP-Windows-10-Pro-(64-bit).dat
2018-07-08 10:11 - 2018-07-08 10:11 - 000000000 ____D C:\RegBackup
2018-07-08 10:11 - 2018-07-08 10:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-07-08 10:10 - 2018-07-08 10:11 - 000194350 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2018-07-08 10:10 - 2018-07-08 10:10 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2018-07-08 10:09 - 2018-07-08 10:10 - 037864128 _____ (Tweaking.com) C:\Users\hometown\Downloads\tweaking.com_windows_repair_aio_setup (1).exe
2018-07-08 09:58 - 2018-07-08 09:58 - 005198336 _____ (AVAST Software) C:\Users\hometown\Downloads\aswMBR.exe
2018-07-08 09:27 - 2018-07-06 23:33 - 000454646 ____R C:\Windows\system32\Drivers\etc\hosts.20180708-092727.backup
2018-07-08 06:16 - 2018-07-08 06:16 - 001790024 _____ (Malwarebytes) C:\Users\hometown\Downloads\JRT.exe
2018-07-08 06:13 - 2018-07-08 06:15 - 342053048 _____ C:\Users\hometown\Downloads\EmsisoftEmergencyKit.exe
2018-07-07 20:54 - 2018-07-07 20:55 - 037864128 _____ (Tweaking.com) C:\Users\hometown\Downloads\tweaking.com_windows_repair_aio_setup.exe
2018-07-07 20:39 - 2018-06-15 10:49 - 021388856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-07-07 20:39 - 2018-06-14 22:12 - 007519992 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-07-07 20:39 - 2018-06-14 22:03 - 006572000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-07 20:39 - 2018-06-14 21:53 - 025847808 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2018-07-07 20:39 - 2018-06-14 21:47 - 022714368 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-07-07 20:38 - 2018-06-15 10:55 - 002266016 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
2018-07-07 20:38 - 2018-06-15 10:55 - 000542888 _____ C:\Windows\system32\FaceProcessorCore.dll
2018-07-07 20:38 - 2018-06-15 10:54 - 000541600 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-07-07 20:38 - 2018-06-15 10:53 - 000348256 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe
2018-07-07 20:38 - 2018-06-15 10:53 - 000094104 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2018-07-07 20:38 - 2018-06-15 10:50 - 001376576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-07-07 20:38 - 2018-06-15 10:48 - 002395056 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2018-07-07 20:38 - 2018-06-15 10:48 - 000338352 _____ (Microsoft Corporation) C:\Windows\system32\AudioSrvPolicyManager.dll
2018-07-07 20:38 - 2018-06-15 10:35 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2018-07-07 20:38 - 2018-06-15 10:34 - 008623616 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2018-07-07 20:38 - 2018-06-15 10:34 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\DsmUserTask.exe
2018-07-07 20:38 - 2018-06-15 10:34 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\perfnet.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 012710400 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 000182784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpdr.sys
2018-07-07 20:38 - 2018-06-15 10:33 - 000156160 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManagerAPI.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 004708864 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000755712 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.PrinterCustomActions.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000406528 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.CscUnpinTool.exe
2018-07-07 20:38 - 2018-06-15 10:32 - 000301568 _____ (Microsoft Corporation) C:\Windows\system32\AcLayers.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000145920 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2018-07-07 20:38 - 2018-06-15 10:31 - 002193920 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.ModernAppAgent.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 001787392 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 001605632 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 000907776 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2018-07-07 20:38 - 2018-06-15 10:31 - 000220672 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001308672 _____ C:\Windows\system32\FaceProcessor.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001254400 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001186816 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.CommonBridge.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001127936 _____ (Microsoft Corporation) C:\Windows\system32\ApplySettingsTemplateCatalog.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001054720 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001004032 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000878592 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000615424 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 000391680 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2018-07-07 20:38 - 2018-06-15 10:29 - 002084352 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-07-07 20:38 - 2018-06-15 10:29 - 002051072 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2018-07-07 20:38 - 2018-06-15 10:29 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000248832 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSoftwareInstallationClient.dll
2018-07-07 20:38 - 2018-06-15 10:28 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2018-07-07 20:38 - 2018-06-15 10:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2018-07-07 20:38 - 2018-06-15 10:28 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2018-07-07 20:38 - 2018-06-15 10:03 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\UevAppMonitor.exe
2018-07-07 20:38 - 2018-06-15 10:00 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.ModernAppCore.dll
2018-07-07 20:38 - 2018-06-15 08:57 - 001538976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
2018-07-07 20:38 - 2018-06-15 08:25 - 020383720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-07-07 20:38 - 2018-06-15 08:22 - 001026896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-07-07 20:38 - 2018-06-15 08:16 - 002206528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2018-07-07 20:38 - 2018-06-15 08:07 - 011901952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-07-07 20:38 - 2018-06-15 08:06 - 007987712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2018-07-07 20:38 - 2018-06-15 08:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfnet.dll
2018-07-07 20:38 - 2018-06-15 08:04 - 000851968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2018-07-07 20:38 - 2018-06-15 08:04 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcLayers.dll
2018-07-07 20:38 - 2018-06-15 08:04 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 001308160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 000831488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2018-07-07 20:38 - 2018-06-15 08:03 - 000667648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 000485376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 001452544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 000775168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 000704000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2018-07-07 20:38 - 2018-06-15 08:01 - 002015744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-07-07 20:38 - 2018-06-15 08:01 - 000228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2018-07-07 20:38 - 2018-06-15 08:01 - 000080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe
2018-07-07 20:38 - 2018-06-15 06:23 - 001008640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MixedRealityCapture.dll
2018-07-07 20:38 - 2018-06-15 06:23 - 000788992 _____ (Microsoft Corporation) C:\Windows\system32\DHolographicDisplay.dll
2018-07-07 20:38 - 2018-06-15 05:09 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-07 20:38 - 2018-06-15 00:11 - 000611232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2018-07-07 20:38 - 2018-06-15 00:10 - 000048544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys
2018-07-07 20:38 - 2018-06-15 00:03 - 000083360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-07-07 20:38 - 2018-06-14 22:24 - 000482472 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase_enclave.dll
2018-07-07 20:38 - 2018-06-14 22:21 - 001213368 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2018-07-07 20:38 - 2018-06-14 22:21 - 000761440 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 001034632 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 000116632 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandler.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 000093600 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthProxyStub.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000272296 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000269248 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave_secure.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000228768 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthAgent.dll
2018-07-07 20:38 - 2018-06-14 22:16 - 000562080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2018-07-07 20:38 - 2018-06-14 22:16 - 000433560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-07-07 20:38 - 2018-06-14 22:15 - 002718624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-07-07 20:38 - 2018-06-14 22:15 - 002563960 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:15 - 000753152 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2018-07-07 20:38 - 2018-06-14 22:13 - 000510904 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2018-07-07 20:38 - 2018-06-14 22:13 - 000324000 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 001012640 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2018-07-07 20:38 - 2018-06-14 22:12 - 000661152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000491304 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000260896 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000118872 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 006817872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 001174424 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2018-07-07 20:38 - 2018-06-14 22:11 - 001018616 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 000134560 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 001934400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 001097640 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000717208 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_StorageSense.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000567176 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2018-07-07 20:38 - 2018-06-14 22:10 - 000326024 _____ (Microsoft Corporation) C:\Windows\system32\ExecModelClient.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000170904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 009147800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-07-07 20:38 - 2018-06-14 22:09 - 007436120 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 002830240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 002546592 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 002422688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 001945784 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001798552 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001742272 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001659296 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001209800 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001112600 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 000885848 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 000709848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 000594128 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2018-07-07 20:38 - 2018-06-14 22:09 - 000247984 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2018-07-07 20:38 - 2018-06-14 22:08 - 004403304 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002753040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002570712 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002371392 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002062488 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001946752 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001921944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2018-07-07 20:38 - 2018-06-14 22:08 - 001784584 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001457128 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-07-07 20:38 - 2018-06-14 22:08 - 001288840 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001258280 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 001150408 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001148800 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001140568 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-07-07 20:38 - 2018-06-14 22:08 - 000983008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 000945568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2018-07-07 20:38 - 2018-06-14 22:08 - 000898760 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000642088 _____ (Microsoft Corporation) C:\Windows\system32\msvcp_win.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000604576 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 000500552 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000413816 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000072768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WindowsTrustedRT.sys
2018-07-07 20:38 - 2018-06-14 22:07 - 001611584 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2018-07-07 20:38 - 2018-06-14 22:07 - 001145696 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2018-07-07 20:38 - 2018-06-14 22:05 - 000550608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-07-07 20:38 - 2018-06-14 22:05 - 000444240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 002331576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001462824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001397192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001251736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000719552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000281080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExecModelClient.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000105376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 006528600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 006043600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 004788504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002535032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002242208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002163184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001981384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001805752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001710240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001620872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001559368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001380192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001175056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001144120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001129640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001020160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001011968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000988128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000770152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000567144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000472136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000356960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000232488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2018-07-07 20:38 - 2018-06-14 22:03 - 000129192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-07-07 20:38 - 2018-06-14 21:56 - 022003712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2018-07-07 20:38 - 2018-06-14 21:50 - 019403264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-07-07 20:38 - 2018-06-14 21:49 - 002962944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2018-07-07 20:38 - 2018-06-14 21:48 - 002900992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2018-07-07 20:38 - 2018-06-14 21:48 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Diagnostics.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 001360384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000622080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000515072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 005780992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004706816 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004371456 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 001356800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 001295872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 002548736 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe
2018-07-07 20:38 - 2018-06-14 21:45 - 000992768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000871424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2018-07-07 20:38 - 2018-06-14 21:45 - 000835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000615424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000578560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000193536 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000019968 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandlerPS.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 001342976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000873472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000295424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
2018-07-07 20:38 - 2018-06-14 21:44 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000185344 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000135680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\smartscreenps.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\updatecsp.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\wcimage.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cellulardatacapabilityhandler.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001626624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001110528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000426496 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2018-07-07 20:38 - 2018-06-14 21:43 - 000312832 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticLogCSP.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\RdpRelayTransport.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000208384 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000191488 _____ (Microsoft Corporation) C:\Windows\system32\VideoHandlers.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000171520 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2018-07-07 20:38 - 2018-06-14 21:43 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 003392512 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 002367488 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000978432 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000558592 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000431104 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000386048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Diagnostics.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000319488 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2018-07-07 20:38 - 2018-06-14 21:42 - 000273920 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-07-07 20:38 - 2018-06-14 21:42 - 000216064 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-07-07 20:38 - 2018-06-14 21:42 - 000102400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 004561920 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 003320320 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 001768448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 001724928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000953856 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2018-07-07 20:38 - 2018-06-14 21:41 - 000898560 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000898560 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000894464 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000814592 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000811520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000625152 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000270336 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManager.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000265728 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 007581696 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001550848 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001487360 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000827392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\dsreg.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\smartscreenps.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002903040 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002583552 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002172416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 001535488 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 001303040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000916992 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000847360 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000684544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 002236928 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2018-07-07 20:38 - 2018-06-14 21:38 - 001854976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001804288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001581568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001305088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001070080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001036288 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000910848 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000596480 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2018-07-07 20:38 - 2018-06-14 21:37 - 001374208 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2018-07-07 20:38 - 2018-06-14 21:37 - 001069056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2018-07-07 20:38 - 2018-06-14 21:37 - 000883712 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-07-07 20:38 - 2018-06-14 21:36 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2018-07-07 20:38 - 2018-06-14 20:23 - 000001310 _____ C:\Windows\system32\tcbres.wim
2018-07-07 20:38 - 2018-05-31 22:18 - 000058524 _____ C:\Windows\system32\srms.dat
2018-07-07 20:38 - 2018-05-20 04:53 - 000792984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2018-07-07 20:38 - 2018-05-20 04:52 - 000413080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-07-07 20:12 - 2018-07-07 20:12 - 000000000 ____D C:\Windows\Firmware
2018-07-07 18:25 - 2018-07-07 18:29 - 000000400 __RSH C:\ProgramData\ntuser.pol
2018-07-07 18:25 - 2018-07-07 18:25 - 001018424 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Users\hometown\Downloads\rufus-3.1.exe
2018-07-07 18:17 - 2018-07-07 18:20 - 703033344 _____ C:\Users\hometown\Downloads\rescue-system.iso
2018-07-07 16:08 - 2018-07-07 16:18 - 000000000 ____D C:\AdwCleaner
2018-07-07 16:08 - 2018-07-07 16:08 - 007395536 _____ (Malwarebytes) C:\Users\hometown\Downloads\AdwCleaner.exe
2018-07-07 11:45 - 2018-07-07 11:45 - 000000000 _____ C:\Users\hometown\Desktop\New Text Document.txt
2018-07-07 09:21 - 2018-07-07 09:21 - 000000000 ____D C:\Users\hometown\AppData\Local\PeerDistRepub
2018-07-07 03:44 - 2018-07-07 03:44 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-07 03:44 - 2018-07-07 03:44 - 000002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-07-07 03:43 - 2018-07-07 03:52 - 000000000 ____D C:\Users\hometown\AppData\Local\Google
2018-07-07 03:43 - 2018-07-07 03:44 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-07 03:43 - 2018-07-07 03:43 - 000003418 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-07-07 03:43 - 2018-07-07 03:43 - 000003294 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-07-07 02:28 - 2018-07-07 02:28 - 000000000 ____D C:\ProgramData\Packages
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\ProgramData\ESET
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\Program Files\ESET
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Windows\system32\Intel
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Windows\system32\cAVS
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Users\hometown\Desktop\estat av
2018-07-07 00:35 - 2018-07-07 00:35 - 000000000 ____D C:\Users\hometown\AppData\Local\ElevatedDiagnostics
2018-07-06 23:55 - 2018-07-06 23:55 - 000000000 ____D C:\Users\hometown\AppData\Local\ESET
2018-07-06 23:54 - 2018-07-06 23:54 - 000000000 ____D C:\Users\hometown\AppData\Local\NVIDIA Corporation
2018-07-06 23:33 - 2018-04-11 16:36 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20180706-233322.backup
2018-07-06 23:20 - 2018-07-06 23:21 - 000000000 ____D C:\Users\hometown\AppData\Local\CrashDumps
2018-07-06 23:20 - 2018-07-06 23:20 - 000000000 ____D C:\Users\hometown\AppData\Local\DBG
2018-07-06 23:13 - 2018-06-08 12:02 - 004527680 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2018-07-06 23:13 - 2018-06-08 11:43 - 002922496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2018-07-06 23:13 - 2018-06-08 03:31 - 007900984 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2018-07-06 23:13 - 2018-06-08 02:30 - 001017080 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2018-07-06 23:13 - 2018-06-08 02:12 - 000861616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2018-07-06 23:13 - 2018-06-08 01:59 - 004867072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-07-06 23:13 - 2018-05-20 09:59 - 023862784 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
2018-07-06 23:13 - 2018-05-20 04:34 - 016592384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2018-07-06 23:13 - 2018-05-20 04:30 - 008188928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2018-07-06 23:13 - 2018-05-20 04:26 - 003392512 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2018-07-06 23:13 - 2018-05-20 04:23 - 013873152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2018-07-06 23:13 - 2018-05-20 04:16 - 006661120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2018-07-06 23:13 - 2018-04-28 04:17 - 019525120 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2018-07-06 23:12 - 2018-06-08 12:07 - 000506184 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2018-07-06 23:12 - 2018-06-08 12:07 - 000183712 _____ (Microsoft Corporation) C:\Windows\system32\mavinject.exe
2018-07-06 23:12 - 2018-06-08 12:07 - 000040864 _____ (Microsoft Corporation) C:\Windows\system32\AppVClientPS.dll
2018-07-06 23:12 - 2018-06-08 12:07 - 000019872 _____ (Microsoft Corporation) C:\Windows\system32\AppVTerminator.dll
2018-07-06 23:12 - 2018-06-08 12:02 - 001634808 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2018-07-06 23:12 - 2018-06-08 12:02 - 000661160 _____ (Microsoft Corporation) C:\Windows\system32\GenValObj.exe
2018-07-06 23:12 - 2018-06-08 12:01 - 001046944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2018-07-06 23:12 - 2018-06-08 11:47 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2018-07-06 23:12 - 2018-06-08 11:46 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2018-07-06 23:12 - 2018-06-08 11:45 - 004392448 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2018-07-06 23:12 - 2018-06-08 11:45 - 001560576 _____ (Microsoft Corporation) C:\Windows\system32\msdt.exe
2018-07-06 23:12 - 2018-06-08 11:45 - 000808960 _____ C:\Windows\system32\MBR2GPT.EXE
2018-07-06 23:12 - 2018-06-08 11:44 - 001121792 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000625152 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000340992 _____ (Microsoft Corporation) C:\Windows\system32\AcGenral.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\wlidcredprov.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 003640832 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2018-07-06 23:12 - 2018-06-08 11:43 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 001659904 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 001543680 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2018-07-06 23:12 - 2018-06-08 11:42 - 003999232 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2018-07-06 23:12 - 2018-06-08 11:42 - 003653120 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2018-07-06 23:12 - 2018-06-08 11:42 - 000800256 _____ (Microsoft Corporation) C:\Windows\system32\pwcreator.exe
2018-07-06 23:12 - 2018-06-08 11:42 - 000503296 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 002019840 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
2018-07-06 23:12 - 2018-06-08 11:41 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2018-07-06 23:12 - 2018-06-08 11:40 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2018-07-06 23:12 - 2018-06-08 10:07 - 000148896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mavinject.exe
2018-07-06 23:12 - 2018-06-08 10:04 - 001454024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2018-07-06 23:12 - 2018-06-08 09:58 - 000917408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2018-07-06 23:12 - 2018-06-08 09:50 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdt.exe
2018-07-06 23:12 - 2018-06-08 09:47 - 003492864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 002895872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2018-07-06 23:12 - 2018-06-08 09:47 - 001462784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 001032704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 000231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcredprov.dll
2018-07-06 23:12 - 2018-06-08 09:46 - 003444224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2018-07-06 23:12 - 2018-06-08 09:46 - 000908288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2018-07-06 23:12 - 2018-06-08 09:45 - 002401280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcGenral.dll
2018-07-06 23:12 - 2018-06-08 09:06 - 000976384 _____ (Microsoft Corporation) C:\Windows\system32\Spectrum.exe
2018-07-06 23:12 - 2018-06-08 09:05 - 000944640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Mirage.Internal.dll
2018-07-06 23:12 - 2018-06-08 07:00 - 000658432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
2018-07-06 23:12 - 2018-06-08 03:38 - 005821544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2018-07-06 23:12 - 2018-06-08 03:37 - 002417840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2018-07-06 23:12 - 2018-06-08 03:35 - 001613200 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2018-07-06 23:12 - 2018-06-08 03:35 - 000613144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2018-07-06 23:12 - 2018-06-08 03:34 - 001299056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2018-07-06 23:12 - 2018-06-08 03:34 - 000748512 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2018-07-06 23:12 - 2018-06-08 03:31 - 003180176 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2018-07-06 23:12 - 2018-06-08 03:31 - 000029600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\uefi.sys
2018-07-06 23:12 - 2018-06-08 03:30 - 000705440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2018-07-06 23:12 - 2018-06-08 02:31 - 000226720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Ucx01000.sys
2018-07-06 23:12 - 2018-06-08 02:30 - 003296896 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 001363632 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 001063328 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2018-07-06 23:12 - 2018-06-08 02:30 - 000723360 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000722808 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000565152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2018-07-06 23:12 - 2018-06-08 02:30 - 000527264 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2018-07-06 23:12 - 2018-06-08 02:30 - 000194456 _____ (Microsoft Corporation) C:\Windows\system32\skci.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000137568 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 004970360 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 003283408 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 002590400 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2018-07-06 23:12 - 2018-06-08 02:29 - 002462272 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001792808 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001364184 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001190152 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001026976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000678840 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000659096 _____ (Microsoft Corporation) C:\Windows\system32\StateRepository.Core.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000416144 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000375712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000313592 _____ (Microsoft Corporation) C:\Windows\system32\mfsensorgroup.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000266656 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000164768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\vertdll.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000084288 _____ (Microsoft Corporation) C:\Windows\system32\LanguageOverlayUtil.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000057960 _____ (Microsoft Corporation) C:\Windows\system32\kernel.appcore.dll
2018-07-06 23:12 - 2018-06-08 02:12 - 000786176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 002479272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 002307336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2018-07-06 23:12 - 2018-06-08 02:10 - 001988072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000880152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000457152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000097176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 004469832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 002486992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 001584128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 001077504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000607648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000568720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryPS.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000553248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000064648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LanguageOverlayUtil.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000050208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel.appcore.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000906752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000038400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryCore.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mskssrv.sys
2018-07-06 23:12 - 2018-06-08 02:02 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2018-07-06 23:12 - 2018-06-08 02:02 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\edpnotify.exe
2018-07-06 23:12 - 2018-06-08 02:02 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe
2018-07-06 23:12 - 2018-06-08 02:01 - 000342528 _____ (Microsoft Corporation) C:\Windows\system32\browserexport.exe
2018-07-06 23:12 - 2018-06-08 02:01 - 000295424 _____ (Microsoft Corporation) C:\Windows\system32\FSClient.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000294912 _____ (Microsoft Corporation) C:\Windows\system32\TDLMigration.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerCsp.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-07-06 23:12 - 2018-06-08 02:00 - 001285120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000329216 _____ (Microsoft Corporation) C:\Windows\system32\credprovs.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2018-07-06 23:12 - 2018-06-08 02:00 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManagerClient.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-07-06 23:12 - 2018-06-08 01:59 - 006032384 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 001318400 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000983040 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000673792 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000564736 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000456704 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2018-07-06 23:12 - 2018-06-08 01:59 - 000177152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryUpgrade.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 003712512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 001676800 _____ (Microsoft Corporation) C:\Windows\system32\CoreShell.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 000781824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2018-07-06 23:12 - 2018-06-08 01:58 - 000239104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FSClient.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe
2018-07-06 23:12 - 2018-06-08 01:57 - 003348992 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000483328 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2018-07-06 23:12 - 2018-06-08 01:57 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000150016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 005307392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 003293696 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 002364928 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 001395200 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000916480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000908800 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:56 - 000871424 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000869376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000858112 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000715776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000264704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovs.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 003441152 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 002248192 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 002061824 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001242112 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001192448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001171968 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001160192 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000849408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000778752 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-07-06 23:12 - 2018-06-08 01:55 - 000776192 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000652800 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 002789376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001586176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001348096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001128448 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000999936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000950272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000857088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:54 - 000842240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000729088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000646656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAC3ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:53 - 001675264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 001466368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000669696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000648192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000528384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2018-07-06 23:12 - 2018-06-06 11:57 - 003733320 _____ C:\Windows\system32\Windows.Mirage.dll
2018-07-06 23:12 - 2018-06-05 21:20 - 002841312 _____ C:\Windows\SysWOW64\Windows.Mirage.dll
2018-07-06 23:12 - 2018-06-01 16:24 - 000713376 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2018-07-06 23:12 - 2018-06-01 15:54 - 001825792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2018-07-06 23:12 - 2018-05-24 20:24 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-07-06 23:12 - 2018-05-20 12:45 - 000308408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-07-06 23:12 - 2018-05-20 12:42 - 001649760 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2018-07-06 23:12 - 2018-05-20 12:42 - 000759192 _____ (Microsoft Corporation) C:\Windows\system32\LicensingWinRT.dll
2018-07-06 23:12 - 2018-05-20 12:26 - 000486912 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll
2018-07-06 23:12 - 2018-05-20 12:23 - 004070400 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-07-06 23:12 - 2018-05-20 12:23 - 000947712 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2018-07-06 23:12 - 2018-05-20 12:23 - 000899072 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 001665024 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 001292288 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2018-07-06 23:12 - 2018-05-20 12:22 - 000941056 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 000804352 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2018-07-06 23:12 - 2018-05-20 11:20 - 000022936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hvsicontainerservice.dll
2018-07-06 23:12 - 2018-05-20 11:15 - 000653208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicensingWinRT.dll
2018-07-06 23:12 - 2018-05-20 11:14 - 001490144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2018-07-06 23:12 - 2018-05-20 11:02 - 000461312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasplap.dll
2018-07-06 23:12 - 2018-05-20 11:00 - 000864768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2018-07-06 23:12 - 2018-05-20 10:59 - 000863232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2018-07-06 23:12 - 2018-05-20 10:59 - 000747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2018-07-06 23:12 - 2018-05-20 09:45 - 001271296 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
2018-07-06 23:12 - 2018-05-20 09:35 - 000677376 _____ (Microsoft Corporation) C:\Windows\system32\HeadTrackerStorage.dll
2018-07-06 23:12 - 2018-05-20 09:34 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\HoloShellRuntime.dll
2018-07-06 23:12 - 2018-05-20 07:54 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\HoloShellRuntime.dll
2018-07-06 23:12 - 2018-05-20 05:33 - 000105368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2018-07-06 23:12 - 2018-05-20 04:53 - 002178136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 001017088 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 001012408 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 000131232 _____ (Microsoft Corporation) C:\Windows\system32\rmclient.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 000088472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys
2018-07-06 23:12 - 2018-05-20 04:52 - 000735560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2018-07-06 23:12 - 2018-05-20 04:52 - 000347704 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-07-06 23:12 - 2018-05-20 04:52 - 000130456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvsocket.sys
2018-07-06 23:12 - 2018-05-20 04:52 - 000089984 _____ (Microsoft Corporation) C:\Windows\system32\CompPkgSup.dll
2018-07-06 23:12 - 2018-05-20 04:34 - 000861096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll
2018-07-06 23:12 - 2018-05-20 04:33 - 001665920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2018-07-06 23:12 - 2018-05-20 04:33 - 000101288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rmclient.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 001034096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000560488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000286200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000077040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CompPkgSup.dll
2018-07-06 23:12 - 2018-05-20 04:31 - 001456640 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
2018-07-06 23:12 - 2018-05-20 04:28 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2018-07-06 23:12 - 2018-05-20 04:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\AppHostRegistrationVerifier.exe
2018-07-06 23:12 - 2018-05-20 04:28 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-07-06 23:12 - 2018-05-20 04:27 - 000344576 _____ (Microsoft Corporation) C:\Windows\system32\RasMediaManager.dll
2018-07-06 23:12 - 2018-05-20 04:27 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\ApiSetHost.AppExecutionAlias.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000356352 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe
2018-07-06 23:12 - 2018-05-20 04:26 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\TelephonyInteractiveUser.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\MSHEIF.dll
2018-07-06 23:12 - 2018-05-20 04:25 - 000835584 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2018-07-06 23:12 - 2018-05-20 04:25 - 000384000 _____ (Microsoft Corporation) C:\Windows\system32\Phoneutil.dll
2018-07-06 23:12 - 2018-05-20 04:24 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-07-06 23:12 - 2018-05-20 04:24 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\DolbyMATEnc.dll
2018-07-06 23:12 - 2018-05-20 04:23 - 005951488 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2018-07-06 23:12 - 2018-05-20 04:23 - 000933376 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 001371136 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 001210880 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 000960512 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 000783360 _____ (Microsoft Corporation) C:\Windows\system32\DolbyHrtfEnc.dll
2018-07-06 23:12 - 2018-05-20 04:17 - 002699776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-07-06 23:12 - 2018-05-20 04:15 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2018-07-06 23:12 - 2018-05-20 04:15 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSHEIF.dll
2018-07-06 23:12 - 2018-05-20 04:14 - 000167936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtutil.exe
2018-07-06 23:12 - 2018-05-20 04:13 - 004929024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2018-07-06 23:12 - 2018-05-20 04:13 - 000317440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Phoneutil.dll
2018-07-06 23:12 - 2018-05-20 04:12 - 000860160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2018-07-06 23:12 - 2018-05-20 04:11 - 001036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2018-07-06 23:12 - 2018-05-20 04:11 - 001005568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2018-07-06 23:12 - 2018-05-20 01:26 - 000018716 _____ C:\Windows\system32\srms-apr.dat
2018-07-06 23:12 - 2018-05-18 10:08 - 000018716 _____ C:\Windows\SysWOW64\srms-apr.dat
2018-07-06 23:12 - 2018-04-28 07:25 - 000652184 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll
2018-07-06 23:12 - 2018-04-28 07:24 - 000749976 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll
2018-07-06 23:12 - 2018-04-28 07:23 - 000826776 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe
2018-07-06 23:12 - 2018-04-28 07:23 - 000399768 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 013570560 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 000171520 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\SharedPCCSP.dll
2018-07-06 23:12 - 2018-04-28 07:01 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\MixedReality.Broker.dll
2018-07-06 23:12 - 2018-04-28 07:00 - 000695296 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2018-07-06 23:12 - 2018-04-28 06:58 - 001855488 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2018-07-06 23:12 - 2018-04-28 06:18 - 000150016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2018-07-06 23:12 - 2018-04-28 06:17 - 012500992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-07-06 23:12 - 2018-04-28 06:14 - 000581120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
2018-07-06 23:12 - 2018-04-28 06:13 - 001585664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2018-07-06 23:12 - 2018-04-28 06:12 - 001380864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2018-07-06 23:12 - 2018-04-28 03:58 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Analog.dll
2018-07-06 23:12 - 2018-04-27 21:31 - 000473496 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 001565592 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000788216 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000776880 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000494488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2018-07-06 23:12 - 2018-04-27 21:29 - 000382872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2018-07-06 23:12 - 2018-04-27 21:14 - 000434584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2018-07-06 23:12 - 2018-04-27 21:13 - 001426328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2018-07-06 23:12 - 2018-04-27 21:13 - 000665320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2018-07-06 23:12 - 2018-04-27 21:12 - 000606448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000585728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.th.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.win81.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000613376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000474624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-07-06 23:12 - 2018-04-27 21:01 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-07-06 23:12 - 2018-04-27 21:00 - 000143360 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-07-06 23:12 - 2018-04-27 20:59 - 000553984 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationExtensions.dll
2018-07-06 23:12 - 2018-04-27 20:58 - 003086336 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-07-06 23:12 - 2018-04-27 20:57 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-07-06 23:12 - 2018-04-27 20:55 - 001421312 _____ (Microsoft Corporation) C:\Windows\system32\rdpbase.dll
2018-07-06 23:12 - 2018-04-27 20:55 - 000543744 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-07-06 23:12 - 2018-04-27 20:54 - 000561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-07-06 23:12 - 2018-04-27 20:53 - 001235968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpbase.dll
2018-07-06 23:12 - 2018-04-27 20:53 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-07-06 23:12 - 2018-04-27 20:51 - 000524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-07-06 23:12 - 2018-04-27 19:43 - 001953280 _____ C:\Windows\system32\rdpnano.dll
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_SurfaceDTXDriver_02_00_00.Wdf
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SurfacePenDriver_01011.Wdf
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\zh-sg
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\en-sg
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\en-au
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Program Files\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Program Files (x86)\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2018-07-06 22:18 - 2018-07-06 22:18 - 000003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-07-06 22:18 - 2017-10-19 12:20 - 005960824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 002587584 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 001766520 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000607352 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000449656 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000122816 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000082040 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-07-06 22:18 - 2017-10-12 20:11 - 007799931 _____ C:\Windows\system32\nvcoproc.bin
2018-07-06 22:18 - 2017-10-10 16:26 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-07-06 22:18 - 2017-09-13 16:20 - 000798008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2018-07-06 22:18 - 2017-09-13 16:20 - 000490296 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2018-07-06 22:18 - 2017-09-13 16:19 - 000927544 _____ C:\Windows\system32\vulkan-1.dll
2018-07-06 22:18 - 2017-09-13 16:19 - 000591160 _____ C:\Windows\system32\vulkaninfo.exe
2018-07-06 22:17 - 2018-07-08 09:14 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-06 22:17 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-07-06 22:17 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-07-06 22:17 - 2018-07-06 22:17 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-07-06 22:17 - 2017-10-19 12:41 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2018-07-06 22:17 - 2017-09-24 14:31 - 000140280 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2018-07-06 22:12 - 2018-07-06 22:15 - 000000000 ____D C:\Windows\system32\MRT
2018-07-06 22:12 - 2018-07-06 22:12 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-07-06 22:12 - 2018-07-06 22:12 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-07-06 22:09 - 2018-07-06 22:09 - 000001464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2018-07-06 22:09 - 2018-07-06 22:09 - 000001452 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2018-07-06 22:09 - 2018-07-06 22:09 - 000000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2018-07-06 22:09 - 2018-07-06 22:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2018-07-06 22:09 - 2018-02-06 19:04 - 000032168 _____ (Safer-Networking Ltd.) C:\Windows\system32\sdnclean64.exe
2018-07-06 22:08 - 2018-07-07 20:43 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\TeaTimer (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\SDHelper (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\Misc. Support Library (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\File Scanner Library (Spybot - Search & Destroy)
2018-07-06 18:38 - 2018-07-06 18:07 - 000548000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-07-06 18:28 - 2018-07-06 23:32 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2018-07-06 18:28 - 2018-07-06 22:06 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2018-07-06 18:08 - 2018-07-08 09:28 - 000000000 ___HD C:\Users\hometown\MicrosoftEdgeBackups
2018-07-06 18:08 - 2018-07-07 11:14 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-07-06 18:07 - 2018-07-06 18:27 - 000000000 ____D C:\ProgramData\RogueKiller
2018-07-06 18:07 - 2018-07-06 18:07 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-07-06 18:07 - 2018-07-06 18:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-07-06 18:07 - 2018-07-06 18:07 - 000000000 ____D C:\Program Files\RogueKiller
2018-07-06 16:17 - 2018-07-07 20:14 - 000000000 ____D C:\Users\hometown\AppData\Local\PlaceholderTileLogoFolder
2018-07-06 13:48 - 2018-07-06 14:07 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-07-06 06:04 - 2018-07-06 05:05 - 000000000 ____D C:\Windows\Panther
2018-07-06 05:26 - 2018-07-06 05:26 - 000000000 ____D C:\Users\hometown\AppData\Local\Comms
2018-07-06 05:11 - 2018-07-08 09:29 - 000000000 ____D C:\Users\hometown\AppData\Local\D3DSCache
2018-07-06 05:11 - 2018-07-07 02:38 - 000000000 ___RD C:\Users\hometown\OneDrive
2018-07-06 05:11 - 2018-07-06 05:11 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-07-06 05:10 - 2018-07-08 09:30 - 000793700 _____ C:\Windows\system32\PerfStringBackup.INI
2018-07-06 05:10 - 2018-07-07 00:32 - 000000000 ____D C:\Users\hometown\AppData\Local\MicrosoftEdge
2018-07-06 05:10 - 2018-07-06 05:10 - 000001417 _____ C:\Users\hometown\Desktop\Microsoft Edge.lnk
2018-07-06 05:09 - 2018-07-07 20:43 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-06 05:09 - 2018-07-07 20:43 - 000000000 ___RD C:\Users\hometown\3D Objects
2018-07-06 05:09 - 2018-07-07 20:12 - 000000000 ____D C:\Users\hometown\AppData\Local\Publishers
2018-07-06 05:09 - 2018-07-07 20:12 - 000000000 ____D C:\Users\hometown\AppData\Local\Packages
2018-07-06 05:09 - 2018-07-07 14:08 - 000000000 ____D C:\Users\hometown\AppData\Local\ConnectedDevicesPlatform
2018-07-06 05:09 - 2018-07-06 19:51 - 000000000 ____D C:\Users\hometown\AppData\Local\VirtualStore
2018-07-06 05:09 - 2018-07-06 18:08 - 000000000 ____D C:\Users\hometown
2018-07-06 05:09 - 2018-07-06 05:09 - 000000020 ___SH C:\Users\hometown\ntuser.ini
2018-07-06 05:09 - 2018-07-06 05:09 - 000000000 ____D C:\Users\hometown\AppData\Roaming\Adobe
2018-07-06 05:08 - 2018-07-06 05:08 - 000000000 ____D C:\Windows\CSC
2018-07-06 05:08 - 2018-07-06 05:08 - 000000000 ____D C:\ProgramData\USOShared
2018-07-06 05:08 - 2018-04-11 16:33 - 002752000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2018-07-06 05:06 - 2018-07-06 05:06 - 000000000 _SHDL C:\Documents and Settings
2018-07-06 05:04 - 2018-07-08 05:51 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-07-06 05:04 - 2018-07-07 20:43 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-07-06 05:04 - 2018-07-06 23:51 - 000233856 _____ C:\Windows\system32\FNTCACHE.DAT
2018-07-06 05:04 - 2018-07-06 22:20 - 000000000 ____D C:\Windows\system32\Drivers\wd
2018-07-06 05:04 - 2018-07-06 05:04 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2018-07-06 05:04 - 2018-07-06 05:04 - 000000000 ____D C:\Windows\ServiceProfiles
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-08 09:30 - 2018-04-11 16:36 - 000000000 ____D C:\Windows\INF
2018-07-08 09:26 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\zu-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\yo-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\xh-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\wo-SN
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\uz-Latn-UZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tn-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ti-ET
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tg-Cyrl-TJ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sr-Cyrl-RS
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sr-Cyrl-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sd-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\rw-RW
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\quc-Latn-GT
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\pa-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\nso-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ku-Arab-IQ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ig-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ha-Latn-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\chr-CHER-US
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ca-ES-valencia
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bs-Latn-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\az-Latn-AZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\zu-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\yo-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\xh-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\wo-SN
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\uz-Latn-UZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tn-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ti-ET
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tg-Cyrl-TJ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sr-Cyrl-RS
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sr-Cyrl-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sd-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\rw-RW
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\quc-Latn-GT
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\pa-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\nso-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ku-Arab-IQ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ig-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ha-Latn-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\chr-CHER-US
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ca-ES-valencia
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bs-Latn-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\az-Latn-AZ
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\appraiser
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\bcastdvr
2018-07-07 20:43 - 2018-04-11 14:04 - 000524288 _____ C:\Windows\system32\config\BBI
2018-07-07 20:40 - 2018-04-11 16:30 - 000000000 ____D C:\Windows\CbsTemp
2018-07-07 20:14 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\AppReadiness
2018-07-07 20:12 - 2018-04-11 16:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-07 18:25 - 2018-04-11 16:38 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-07-07 18:25 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-07-07 12:30 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\LiveKernelReports
2018-07-07 03:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\appcompat
2018-07-06 23:51 - 2018-04-12 02:37 - 000000000 ____D C:\Windows\Containers
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\vi-VN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ur-PK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ug-CN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tt-RU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tk-TM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\te-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ta-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sw-KE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sq-AL
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\si-LK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\quz-PE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\prs-AF
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\pa-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\or-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\nn-NO
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ne-NP
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mt-MT
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mr-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mn-MN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ml-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mk-MK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mi-NZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\lo-LA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\lb-LU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ky-KG
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kok-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\km-KH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kk-KZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ka-GE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\is-IS
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\id-ID
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\hy-AM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\gu-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\gd-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ga-IE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\fil-PH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\fa-IR
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\cy-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bn-BD
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\be-BY
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\as-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\am-ET
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\af-ZA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\vi-VN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ur-PK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ug-CN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tt-RU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tk-TM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\te-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sw-KE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sq-AL
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\quz-PE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\prs-AF
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\pa-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\or-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\nn-NO
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ne-NP
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mt-MT
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mr-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mn-MN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ml-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mk-MK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mi-NZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\lo-LA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\lb-LU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ky-KG
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kok-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\km-KH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kk-KZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ka-GE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\is-IS
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\id-ID
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\hy-AM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\gu-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\gd-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ga-IE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\fil-PH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\fa-IR
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\cy-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bn-BD
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\be-BY
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\as-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\af-ZA
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\TextInput
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\setup
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\ta-in
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\si-lk
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\setup
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\oobe
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\am-et
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\ShellExperiences
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\Provisioning
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-07-06 23:51 - 2018-04-11 14:04 - 000000000 ____D C:\Windows\system32\Dism
2018-07-06 22:20 - 2018-04-11 16:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-07-06 22:19 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\es-MX
2018-07-06 22:19 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\en-GB
2018-07-06 22:17 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\Help
2018-07-06 19:47 - 2018-04-11 16:38 - 000000076 _____ C:\Windows\win.ini
2018-07-06 06:04 - 2018-04-11 16:38 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2018-07-06 05:09 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\spool
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\FxsTmp
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\USOPrivate
2018-07-06 05:04 - 2018-04-11 16:38 - 000000000 ___RD C:\Windows\PrintDialog
2018-07-06 05:04 - 2018-04-11 14:04 - 000032768 _____ C:\Windows\system32\config\ELAM
Some files in TEMP:
====================
2018-07-06 23:21 - 2018-07-06 23:21 - 000437120 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\BAP.exe
2018-07-06 18:07 - 2018-06-08 02:29 - 001946328 _____ (Microsoft Corporation) C:\Users\hometown\AppData\Local\Temp\dllnt_dump.dll
2018-07-06 23:20 - 2018-07-06 23:20 - 000592768 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\EKLXTWJ.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000580480 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\SEITI.exe
2018-07-06 23:20 - 2018-07-06 23:20 - 000494464 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\VL.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000461696 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\YBQJLPCWBJEEM.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000457600 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\ZGMG.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-07-06 05:04
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by hometown (08-07-2018 10:26:42)
Running from C:\Users\hometown\Desktop
Windows 10 Pro Version 1803 17134.137 (X64) (2018-07-06 12:06:18)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2251815794-2661967540-3884843598-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2251815794-2661967540-3884843598-503 - Limited - Disabled)
Guest (S-1-5-21-2251815794-2661967540-3884843598-501 - Limited - Disabled)
hometown (S-1-5-21-2251815794-2661967540-3884843598-1001 - Administrator - Enabled) => C:\Users\hometown
WDAGUtilityAccount (S-1-5-21-2251815794-2661967540-3884843598-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 388.08 - NVIDIA Corporation) Hidden
ESET Endpoint Antivirus (HKLM\...\{3187B3B0-3620-4459-A983-4403FC481420}) (Version: 5.0.2214.4 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
NVIDIA Graphics Driver 388.08 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.08 - NVIDIA Corporation)
NVIDIA Update 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation)
RogueKiller version 12.12.25.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.25.0 - Adlice Software)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.22 - Tweaking.com)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-10-19] (NVIDIA Corporation)
ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {019CE806-0B74-40ED-ADD1-BE273A3DF3AB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-07] (Google Inc.)
Task: {07C89F96-897E-4E07-805C-8B5F92982B8E} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
Task: {1D9DF227-07F6-4130-A594-438A37B571AD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {281A2E0B-9528-47D7-8BED-F225577B499E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-10] (NVIDIA Corporation)
Task: {57362581-68DE-4AC5-896F-704CD50FB24E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {632BE4C5-384B-4425-9E20-48897F2194F7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-07] (Google Inc.)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {7C5D6F45-4540-49C5-AC37-FBD2C7298932} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {9C59F3C3-831D-4EB8-93AF-405EBA2301FE} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2017-05-02] (Tweaking.com)
Task: {A7BC178E-570C-4378-9ED0-CFB4EBE51C87} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {C71348F5-0B6B-40C2-800F-17A705E8EF74} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {EEA0CED9-3B52-4D03-9492-66CB27B9E490} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-04-11 16:34 - 2018-04-11 16:34 - 000253440 _____ () C:\Windows\System32\HeatCore.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000133568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-11-01 10:52 - 2017-11-01 10:52 - 000804744 _____ () C:\Windows\System32\SurfaceDTX.exe
2018-07-06 22:09 - 2018-02-05 16:57 - 000436016 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com (http://www.008k.com)
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com (http://www.00hq.com)
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com (http://www.0scan.com)
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com (http://www.1-2005-search.com)
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com (http://www.1-domains-registrations.com)
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com (http://www.1000gratisproben.com)
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com (http://www.1001namen.com)
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com (http://www.100sexlinks.com)
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com (http://www.10sek.com)
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info (http://www.123fporn.info)
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com (http://www.123moviedownload.com)
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com (http://www.123simsen.com)
There are 7939 more sites.
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\008k.com -> www.008k.com (http://www.008k.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\00hq.com -> www.00hq.com (http://www.00hq.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\0scan.com -> www.0scan.com (http://www.0scan.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1-2005-search.com -> www.1-2005-search.com (http://www.1-2005-search.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com (http://www.1-domains-registrations.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1000gratisproben.com -> www.1000gratisproben.com (http://www.1000gratisproben.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1001namen.com -> www.1001namen.com (http://www.1001namen.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\100sexlinks.com -> www.100sexlinks.com (http://www.100sexlinks.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\10sek.com -> www.10sek.com (http://www.10sek.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123fporn.info -> www.123fporn.info (http://www.123fporn.info)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123moviedownload.com -> www.123moviedownload.com (http://www.123moviedownload.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123simsen.com -> www.123simsen.com (http://www.123simsen.com)
There are 7939 more sites.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-11 16:38 - 2018-07-08 09:27 - 000454646 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com (http://www.007guard.com)
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com (http://www.008k.com)
127.0.0.1 008k.com
127.0.0.1 www.00hq.com (http://www.00hq.com)
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com (http://www.032439.com)
127.0.0.1 032439.com
127.0.0.1 www.0scan.com (http://www.0scan.com)
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com (http://www.1000gratisproben.com)
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com (http://www.1001namen.com)
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com (http://www.100888290cs.com)
127.0.0.1 www.100sexlinks.com (http://www.100sexlinks.com)
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com (http://www.10sek.com)
127.0.0.1 www.1-2005-search.com (http://www.1-2005-search.com)
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info (http://www.123fporn.info)
127.0.0.1 www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com (http://www.123moviedownload.com)
There are 15605 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{35C00080-07FF-47BB-8747-520CB904D74A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/07/2018 08:43:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IntelAudioService.exe, version: 1.0.46.0, time stamp: 0x59afa72c
Faulting module name: KERNELBASE.dll, version: 10.0.17134.137, time stamp: 0x7745a173
Exception code: 0xe0434352
Fault offset: 0x000000000003a388
Faulting process id: 0xdd4
Faulting application start time: 0x01d4166dd89f001f
Faulting application path: C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: cd7aa138-04b7-4344-a380-7c276128dcc6
Faulting package full name:
Faulting package-relative application ID:
Error: (07/07/2018 08:43:35 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.DllNotFoundException
at IntelAudioService.Logger.AudioServiceLogger.SetLogMessageDelegate(LoggerDelegate)
at IntelAudioService.Logger.AudioServiceLogger..ctor()
at IntelAudioService.Logger.AudioServiceLogger.get_Instance()
at IntelAudioService.AudioService..ctor()
at IntelAudioService.Program.Main()
Error: (07/07/2018 08:14:22 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:14:20 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:14:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IntelAudioService.exe, version: 1.0.46.0, time stamp: 0x59afa72c
Faulting module name: KERNELBASE.dll, version: 10.0.17134.112, time stamp: 0xf2b2cb6c
Exception code: 0xe0434352
Fault offset: 0x000000000003a388
Faulting process id: 0xea4
Faulting application start time: 0x01d41669bbb93939
Faulting application path: C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 7943ae0d-afe4-40c9-8103-2353cb6a9533
Faulting package full name:
Faulting package-relative application ID:
Error: (07/07/2018 08:14:07 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.DllNotFoundException
at IntelAudioService.Logger.AudioServiceLogger.SetLogMessageDelegate(LoggerDelegate)
at IntelAudioService.Logger.AudioServiceLogger..ctor()
at IntelAudioService.Logger.AudioServiceLogger.get_Instance()
at IntelAudioService.AudioService..ctor()
at IntelAudioService.Program.Main()
Error: (07/07/2018 08:09:31 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(15ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:09:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (07/08/2018 10:23:42 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:27:43 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:02 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
Error: (07/07/2018 08:50:22 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/07/2018 08:43:47 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/07/2018 08:43:47 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Windows Defender:
===================================
Date: 2018-07-06 19:58:52.993
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.643.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2018-07-06 17:58:47.774
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.773
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.773
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.678
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-6600U CPU @ 2.60GHz
Percentage of memory in use: 21%
Total physical RAM: 16309.29 MB
Available physical RAM: 12804.39 MB
Total Virtual: 19253.29 MB
Available Virtual: 12886.38 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:476.34 GB) (Free:444.58 GB) NTFS
\\?\Volume{9e7df45b-cb0b-47d8-912e-9ef5e4e8a6dc}\ (Recovery) (Fixed) (Total:0.49 GB) (Free:0.13 GB) NTFS
\\?\Volume{432b50d5-0a2c-444f-b184-77bfde5d7507}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
Run date: 2018-07-08 11:03:07
-----------------------------
11:03:07.636 OS Version: Windows x64 6.2.9200
11:03:07.636 Number of processors: 4 586 0x4E03
11:03:07.636 ComputerName: DESKTOP-VTV5VMP UserName: hometown
11:03:07.904 Initialize success
11:03:07.920 VM: initialized successfully
11:03:07.920 VM: Intel CPU supported
11:03:11.984 VM: not used
11:03:42.722 AVAST engine defs: 17030301
11:03:48.939 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003a
11:03:48.939 Disk 0 Vendor: SAMSUNG_MZFLV512HCJH-000MV BXV75M0Q Size: 488386MB BusType: 17
11:03:48.954 Disk 0 MBR read successfully
11:03:48.954 Disk 0 MBR scan
11:03:48.970 Disk 0 unknown MBR code
11:03:48.970 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
11:03:48.970 Disk 0 scanning C:\Windows\system32\drivers
11:03:48.986 Service scanning
11:04:12.856 Modules scanning
11:04:13.122 AVAST engine scan C:\Windows
11:04:13.122 AVAST engine scan C:\Windows\system32
11:04:13.137 AVAST engine scan C:\Windows\system32\drivers
11:04:13.137 AVAST engine scan C:\Users\hometown
11:04:13.137 AVAST engine scan C:\ProgramData
11:04:13.153 Scan finished successfully
11:05:21.612 Disk 0 MBR has been saved successfully to "C:\Users\hometown\Desktop\MBR.dat"
11:05:21.628 The log file has been saved successfully to "C:\Users\hometown\Desktop\aswMBR.txt"
I tried to run this with the virtulization and it would crash I also could not run it with trace disk io calls.
I have tried malwarebyted, esat, spybot, tweaker.com and several others in my futile attempt to fix this problem. I am sure it is on my network and has spread to two other computers.
Thank you for the help I am lost and sad.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by hometown (administrator) on DESKTOP-VTV5VMP (08-07-2018 10:26:18)
Running from C:\Users\hometown\Desktop
Loaded Profiles: hometown (Available Profiles: hometown)
Platform: Windows 10 Pro Version 1803 17134.137 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64gh4811.inf_amd64_f02d96a3e7a6ed57\IntelCpHDCPSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64gh4811.inf_amd64_f02d96a3e7a6ed57\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\SurfaceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Windows\System32\SurfaceDTX.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.136_none_eb1580521d543895\TiWorker.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [SurfaceDTX.exe] => C:\Windows\System32\SurfaceDTX.exe [804744 2017-11-01] ()
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4144944 2013-02-14] (ESET)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{7111250b-1515-4e75-928c-6e3c5d4171a3}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
StartMenuInternet: IEXPLORE.EXE -
FireFox:
========
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: (ESET Endpoint Security Extension) - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2018-07-07] [Legacy] [not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-07] (Google Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Profile: C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default [2018-07-08]
CHR Extension: (Slides) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-07]
CHR Extension: (Docs) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-07]
CHR Extension: (Google Drive) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-07]
CHR Extension: (DuckDuckGo) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2018-07-07]
CHR Extension: (YouTube) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-07]
CHR Extension: (Sheets) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-07]
CHR Extension: (Google Docs Offline) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-07]
CHR Extension: (Gmail) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-07]
CHR Extension: (Chrome Media Router) - C:\Users\hometown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [40888 2013-02-14] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1020304 2013-02-14] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [190208 2013-02-14] (ESET)
S2 IntelAudioService; C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe [161880 2017-10-03] (Intel)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S2 SurfaceDtxService; C:\Windows\system32\SurfaceDtxService.exe [91016 2017-11-01] (Microsoft Corporation)
S2 SurfaceUsbHubFwUpdateService; C:\Windows\System32\SurfaceUsbHubFwUpdateService.exe [942360 2016-12-06] (Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-07-06] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-07-06] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [217000 2013-02-04] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [183016 2013-04-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [153200 2013-02-04] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [141304 2013-02-04] (ESET)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvmso.inf_amd64_b89aa41766002e30\nvlddmkm.sys [16925296 2017-10-31] (NVIDIA Corporation)
S3 smbdirect; C:\Windows\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
S3 SurfaceBaseIntegration; C:\Windows\System32\drivers\SurfaceBaseIntegration.sys [68144 2016-04-11] (Microsoft Corporation)
R0 SurfaceUsbHubFwUpdate; C:\Windows\System32\drivers\SurfaceUsbHubFwUpdate.sys [71448 2016-12-06] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46592 2018-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [340008 2018-07-06] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59944 2018-07-06] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-08 10:26 - 2018-07-08 10:26 - 000011415 _____ C:\Users\hometown\Desktop\FRST.txt
2018-07-08 10:14 - 2018-07-08 10:26 - 000000000 ____D C:\FRST
2018-07-08 10:13 - 2018-07-08 10:13 - 002412544 _____ (Farbar) C:\Users\hometown\Desktop\FRST64.exe
2018-07-08 10:11 - 2018-07-08 10:11 - 000003788 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2018-07-08 10:11 - 2018-07-08 10:11 - 000002236 _____ C:\Users\hometown\Desktop\Tweaking.com - Windows Repair.lnk
2018-07-08 10:11 - 2018-07-08 10:11 - 000000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-VTV5VMP-Windows-10-Pro-(64-bit).dat
2018-07-08 10:11 - 2018-07-08 10:11 - 000000000 ____D C:\RegBackup
2018-07-08 10:11 - 2018-07-08 10:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-07-08 10:10 - 2018-07-08 10:11 - 000194350 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2018-07-08 10:10 - 2018-07-08 10:10 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2018-07-08 10:09 - 2018-07-08 10:10 - 037864128 _____ (Tweaking.com) C:\Users\hometown\Downloads\tweaking.com_windows_repair_aio_setup (1).exe
2018-07-08 09:58 - 2018-07-08 09:58 - 005198336 _____ (AVAST Software) C:\Users\hometown\Downloads\aswMBR.exe
2018-07-08 09:27 - 2018-07-06 23:33 - 000454646 ____R C:\Windows\system32\Drivers\etc\hosts.20180708-092727.backup
2018-07-08 06:16 - 2018-07-08 06:16 - 001790024 _____ (Malwarebytes) C:\Users\hometown\Downloads\JRT.exe
2018-07-08 06:13 - 2018-07-08 06:15 - 342053048 _____ C:\Users\hometown\Downloads\EmsisoftEmergencyKit.exe
2018-07-07 20:54 - 2018-07-07 20:55 - 037864128 _____ (Tweaking.com) C:\Users\hometown\Downloads\tweaking.com_windows_repair_aio_setup.exe
2018-07-07 20:39 - 2018-06-15 10:49 - 021388856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-07-07 20:39 - 2018-06-14 22:12 - 007519992 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-07-07 20:39 - 2018-06-14 22:03 - 006572000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-07 20:39 - 2018-06-14 21:53 - 025847808 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2018-07-07 20:39 - 2018-06-14 21:47 - 022714368 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-07-07 20:38 - 2018-06-15 10:55 - 002266016 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
2018-07-07 20:38 - 2018-06-15 10:55 - 000542888 _____ C:\Windows\system32\FaceProcessorCore.dll
2018-07-07 20:38 - 2018-06-15 10:54 - 000541600 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-07-07 20:38 - 2018-06-15 10:53 - 000348256 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe
2018-07-07 20:38 - 2018-06-15 10:53 - 000094104 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2018-07-07 20:38 - 2018-06-15 10:50 - 001376576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-07-07 20:38 - 2018-06-15 10:48 - 002395056 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2018-07-07 20:38 - 2018-06-15 10:48 - 000338352 _____ (Microsoft Corporation) C:\Windows\system32\AudioSrvPolicyManager.dll
2018-07-07 20:38 - 2018-06-15 10:35 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2018-07-07 20:38 - 2018-06-15 10:34 - 008623616 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2018-07-07 20:38 - 2018-06-15 10:34 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\DsmUserTask.exe
2018-07-07 20:38 - 2018-06-15 10:34 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\perfnet.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 012710400 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 000182784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpdr.sys
2018-07-07 20:38 - 2018-06-15 10:33 - 000156160 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManagerAPI.dll
2018-07-07 20:38 - 2018-06-15 10:33 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 004708864 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000755712 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.PrinterCustomActions.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000406528 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.CscUnpinTool.exe
2018-07-07 20:38 - 2018-06-15 10:32 - 000301568 _____ (Microsoft Corporation) C:\Windows\system32\AcLayers.dll
2018-07-07 20:38 - 2018-06-15 10:32 - 000145920 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2018-07-07 20:38 - 2018-06-15 10:31 - 002193920 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.ModernAppAgent.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 001787392 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 001605632 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2018-07-07 20:38 - 2018-06-15 10:31 - 000907776 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2018-07-07 20:38 - 2018-06-15 10:31 - 000220672 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001308672 _____ C:\Windows\system32\FaceProcessor.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001254400 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001186816 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.CommonBridge.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 001127936 _____ (Microsoft Corporation) C:\Windows\system32\ApplySettingsTemplateCatalog.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001054720 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 001004032 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000878592 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000615424 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2018-07-07 20:38 - 2018-06-15 10:30 - 000391680 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-07-07 20:38 - 2018-06-15 10:30 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2018-07-07 20:38 - 2018-06-15 10:29 - 002084352 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-07-07 20:38 - 2018-06-15 10:29 - 002051072 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2018-07-07 20:38 - 2018-06-15 10:29 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000248832 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2018-07-07 20:38 - 2018-06-15 10:29 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSoftwareInstallationClient.dll
2018-07-07 20:38 - 2018-06-15 10:28 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2018-07-07 20:38 - 2018-06-15 10:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2018-07-07 20:38 - 2018-06-15 10:28 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2018-07-07 20:38 - 2018-06-15 10:03 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\UevAppMonitor.exe
2018-07-07 20:38 - 2018-06-15 10:00 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.ModernAppCore.dll
2018-07-07 20:38 - 2018-06-15 08:57 - 001538976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
2018-07-07 20:38 - 2018-06-15 08:25 - 020383720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-07-07 20:38 - 2018-06-15 08:22 - 001026896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-07-07 20:38 - 2018-06-15 08:16 - 002206528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2018-07-07 20:38 - 2018-06-15 08:07 - 011901952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-07-07 20:38 - 2018-06-15 08:06 - 007987712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2018-07-07 20:38 - 2018-06-15 08:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfnet.dll
2018-07-07 20:38 - 2018-06-15 08:04 - 000851968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2018-07-07 20:38 - 2018-06-15 08:04 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcLayers.dll
2018-07-07 20:38 - 2018-06-15 08:04 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 001308160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 000831488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2018-07-07 20:38 - 2018-06-15 08:03 - 000667648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-07-07 20:38 - 2018-06-15 08:03 - 000485376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 001452544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 000775168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2018-07-07 20:38 - 2018-06-15 08:02 - 000704000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2018-07-07 20:38 - 2018-06-15 08:01 - 002015744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-07-07 20:38 - 2018-06-15 08:01 - 000228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2018-07-07 20:38 - 2018-06-15 08:01 - 000080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe
2018-07-07 20:38 - 2018-06-15 06:23 - 001008640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MixedRealityCapture.dll
2018-07-07 20:38 - 2018-06-15 06:23 - 000788992 _____ (Microsoft Corporation) C:\Windows\system32\DHolographicDisplay.dll
2018-07-07 20:38 - 2018-06-15 05:09 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-07 20:38 - 2018-06-15 00:11 - 000611232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2018-07-07 20:38 - 2018-06-15 00:10 - 000048544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys
2018-07-07 20:38 - 2018-06-15 00:03 - 000083360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-07-07 20:38 - 2018-06-14 22:24 - 000482472 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase_enclave.dll
2018-07-07 20:38 - 2018-06-14 22:21 - 001213368 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2018-07-07 20:38 - 2018-06-14 22:21 - 000761440 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 001034632 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 000116632 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandler.exe
2018-07-07 20:38 - 2018-06-14 22:19 - 000093600 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthProxyStub.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000272296 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000269248 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave_secure.dll
2018-07-07 20:38 - 2018-06-14 22:18 - 000228768 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthAgent.dll
2018-07-07 20:38 - 2018-06-14 22:16 - 000562080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2018-07-07 20:38 - 2018-06-14 22:16 - 000433560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-07-07 20:38 - 2018-06-14 22:15 - 002718624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-07-07 20:38 - 2018-06-14 22:15 - 002563960 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:15 - 000753152 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2018-07-07 20:38 - 2018-06-14 22:13 - 000510904 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2018-07-07 20:38 - 2018-06-14 22:13 - 000324000 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 001012640 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2018-07-07 20:38 - 2018-06-14 22:12 - 000661152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000491304 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000260896 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-07-07 20:38 - 2018-06-14 22:12 - 000118872 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 006817872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 001174424 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2018-07-07 20:38 - 2018-06-14 22:11 - 001018616 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-07-07 20:38 - 2018-06-14 22:11 - 000134560 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 001934400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 001097640 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000717208 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_StorageSense.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000567176 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2018-07-07 20:38 - 2018-06-14 22:10 - 000326024 _____ (Microsoft Corporation) C:\Windows\system32\ExecModelClient.dll
2018-07-07 20:38 - 2018-06-14 22:10 - 000170904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 009147800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-07-07 20:38 - 2018-06-14 22:09 - 007436120 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 002830240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 002546592 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 002422688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 001945784 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001798552 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001742272 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001659296 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001209800 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 001112600 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 000885848 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2018-07-07 20:38 - 2018-06-14 22:09 - 000709848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-07-07 20:38 - 2018-06-14 22:09 - 000594128 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2018-07-07 20:38 - 2018-06-14 22:09 - 000247984 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2018-07-07 20:38 - 2018-06-14 22:08 - 004403304 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002753040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002570712 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002371392 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 002062488 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001946752 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001921944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2018-07-07 20:38 - 2018-06-14 22:08 - 001784584 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001457128 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-07-07 20:38 - 2018-06-14 22:08 - 001288840 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001258280 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 001150408 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001148800 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 001140568 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-07-07 20:38 - 2018-06-14 22:08 - 000983008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 000945568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2018-07-07 20:38 - 2018-06-14 22:08 - 000898760 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000642088 _____ (Microsoft Corporation) C:\Windows\system32\msvcp_win.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000604576 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2018-07-07 20:38 - 2018-06-14 22:08 - 000500552 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000413816 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2018-07-07 20:38 - 2018-06-14 22:08 - 000072768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WindowsTrustedRT.sys
2018-07-07 20:38 - 2018-06-14 22:07 - 001611584 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2018-07-07 20:38 - 2018-06-14 22:07 - 001145696 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2018-07-07 20:38 - 2018-06-14 22:05 - 000550608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-07-07 20:38 - 2018-06-14 22:05 - 000444240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 002331576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001462824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001397192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 001251736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000719552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000281080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExecModelClient.dll
2018-07-07 20:38 - 2018-06-14 22:04 - 000105376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 006528600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 006043600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 004788504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002535032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002242208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 002163184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001981384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001805752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001710240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001620872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001559368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001380192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001175056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001144120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001129640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001020160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 001011968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000988128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000770152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000567144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000472136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000356960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2018-07-07 20:38 - 2018-06-14 22:03 - 000232488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2018-07-07 20:38 - 2018-06-14 22:03 - 000129192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-07-07 20:38 - 2018-06-14 21:56 - 022003712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2018-07-07 20:38 - 2018-06-14 21:50 - 019403264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-07-07 20:38 - 2018-06-14 21:49 - 002962944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2018-07-07 20:38 - 2018-06-14 21:48 - 002900992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2018-07-07 20:38 - 2018-06-14 21:48 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Diagnostics.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 001360384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000622080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000515072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2018-07-07 20:38 - 2018-06-14 21:47 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 005780992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004706816 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004371456 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 004333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 001356800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 001295872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2018-07-07 20:38 - 2018-06-14 21:46 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 002548736 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe
2018-07-07 20:38 - 2018-06-14 21:45 - 000992768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000871424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2018-07-07 20:38 - 2018-06-14 21:45 - 000835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000615424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000578560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000193536 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll
2018-07-07 20:38 - 2018-06-14 21:45 - 000019968 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandlerPS.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 001342976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000873472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000295424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
2018-07-07 20:38 - 2018-06-14 21:44 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000185344 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000135680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\smartscreenps.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\updatecsp.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\wcimage.dll
2018-07-07 20:38 - 2018-06-14 21:44 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cellulardatacapabilityhandler.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001626624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 001110528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000426496 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2018-07-07 20:38 - 2018-06-14 21:43 - 000312832 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticLogCSP.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\RdpRelayTransport.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000208384 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000191488 _____ (Microsoft Corporation) C:\Windows\system32\VideoHandlers.dll
2018-07-07 20:38 - 2018-06-14 21:43 - 000171520 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2018-07-07 20:38 - 2018-06-14 21:43 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 003392512 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 002367488 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000978432 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000558592 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000431104 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000386048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Diagnostics.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000319488 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2018-07-07 20:38 - 2018-06-14 21:42 - 000273920 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-07-07 20:38 - 2018-06-14 21:42 - 000216064 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2018-07-07 20:38 - 2018-06-14 21:42 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-07-07 20:38 - 2018-06-14 21:42 - 000102400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 004561920 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 003320320 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 001768448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 001724928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000953856 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2018-07-07 20:38 - 2018-06-14 21:41 - 000898560 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000898560 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000894464 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000814592 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000811520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000625152 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000270336 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManager.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000265728 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2018-07-07 20:38 - 2018-06-14 21:41 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 007581696 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001550848 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 001487360 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000827392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\dsreg.dll
2018-07-07 20:38 - 2018-06-14 21:40 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\smartscreenps.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002903040 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002583552 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 002172416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 001535488 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 001303040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000916992 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000847360 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2018-07-07 20:38 - 2018-06-14 21:39 - 000684544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 002236928 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2018-07-07 20:38 - 2018-06-14 21:38 - 001854976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001804288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001581568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001305088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001070080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 001036288 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000910848 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000596480 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2018-07-07 20:38 - 2018-06-14 21:38 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2018-07-07 20:38 - 2018-06-14 21:37 - 001374208 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2018-07-07 20:38 - 2018-06-14 21:37 - 001069056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2018-07-07 20:38 - 2018-06-14 21:37 - 000883712 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-07-07 20:38 - 2018-06-14 21:36 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2018-07-07 20:38 - 2018-06-14 20:23 - 000001310 _____ C:\Windows\system32\tcbres.wim
2018-07-07 20:38 - 2018-05-31 22:18 - 000058524 _____ C:\Windows\system32\srms.dat
2018-07-07 20:38 - 2018-05-20 04:53 - 000792984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2018-07-07 20:38 - 2018-05-20 04:52 - 000413080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-07-07 20:12 - 2018-07-07 20:12 - 000000000 ____D C:\Windows\Firmware
2018-07-07 18:25 - 2018-07-07 18:29 - 000000400 __RSH C:\ProgramData\ntuser.pol
2018-07-07 18:25 - 2018-07-07 18:25 - 001018424 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Users\hometown\Downloads\rufus-3.1.exe
2018-07-07 18:17 - 2018-07-07 18:20 - 703033344 _____ C:\Users\hometown\Downloads\rescue-system.iso
2018-07-07 16:08 - 2018-07-07 16:18 - 000000000 ____D C:\AdwCleaner
2018-07-07 16:08 - 2018-07-07 16:08 - 007395536 _____ (Malwarebytes) C:\Users\hometown\Downloads\AdwCleaner.exe
2018-07-07 11:45 - 2018-07-07 11:45 - 000000000 _____ C:\Users\hometown\Desktop\New Text Document.txt
2018-07-07 09:21 - 2018-07-07 09:21 - 000000000 ____D C:\Users\hometown\AppData\Local\PeerDistRepub
2018-07-07 03:44 - 2018-07-07 03:44 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-07 03:44 - 2018-07-07 03:44 - 000002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-07-07 03:43 - 2018-07-07 03:52 - 000000000 ____D C:\Users\hometown\AppData\Local\Google
2018-07-07 03:43 - 2018-07-07 03:44 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-07 03:43 - 2018-07-07 03:43 - 000003418 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-07-07 03:43 - 2018-07-07 03:43 - 000003294 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-07-07 02:28 - 2018-07-07 02:28 - 000000000 ____D C:\ProgramData\Packages
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\ProgramData\ESET
2018-07-07 02:12 - 2018-07-07 02:12 - 000000000 ____D C:\Program Files\ESET
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Windows\system32\Intel
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Windows\system32\cAVS
2018-07-07 02:11 - 2018-07-07 02:11 - 000000000 ____D C:\Users\hometown\Desktop\estat av
2018-07-07 00:35 - 2018-07-07 00:35 - 000000000 ____D C:\Users\hometown\AppData\Local\ElevatedDiagnostics
2018-07-06 23:55 - 2018-07-06 23:55 - 000000000 ____D C:\Users\hometown\AppData\Local\ESET
2018-07-06 23:54 - 2018-07-06 23:54 - 000000000 ____D C:\Users\hometown\AppData\Local\NVIDIA Corporation
2018-07-06 23:33 - 2018-04-11 16:36 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20180706-233322.backup
2018-07-06 23:20 - 2018-07-06 23:21 - 000000000 ____D C:\Users\hometown\AppData\Local\CrashDumps
2018-07-06 23:20 - 2018-07-06 23:20 - 000000000 ____D C:\Users\hometown\AppData\Local\DBG
2018-07-06 23:13 - 2018-06-08 12:02 - 004527680 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2018-07-06 23:13 - 2018-06-08 11:43 - 002922496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2018-07-06 23:13 - 2018-06-08 03:31 - 007900984 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2018-07-06 23:13 - 2018-06-08 02:30 - 001017080 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2018-07-06 23:13 - 2018-06-08 02:12 - 000861616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2018-07-06 23:13 - 2018-06-08 01:59 - 004867072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-07-06 23:13 - 2018-05-20 09:59 - 023862784 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
2018-07-06 23:13 - 2018-05-20 04:34 - 016592384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2018-07-06 23:13 - 2018-05-20 04:30 - 008188928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2018-07-06 23:13 - 2018-05-20 04:26 - 003392512 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2018-07-06 23:13 - 2018-05-20 04:23 - 013873152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2018-07-06 23:13 - 2018-05-20 04:16 - 006661120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2018-07-06 23:13 - 2018-04-28 04:17 - 019525120 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2018-07-06 23:12 - 2018-06-08 12:07 - 000506184 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2018-07-06 23:12 - 2018-06-08 12:07 - 000183712 _____ (Microsoft Corporation) C:\Windows\system32\mavinject.exe
2018-07-06 23:12 - 2018-06-08 12:07 - 000040864 _____ (Microsoft Corporation) C:\Windows\system32\AppVClientPS.dll
2018-07-06 23:12 - 2018-06-08 12:07 - 000019872 _____ (Microsoft Corporation) C:\Windows\system32\AppVTerminator.dll
2018-07-06 23:12 - 2018-06-08 12:02 - 001634808 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2018-07-06 23:12 - 2018-06-08 12:02 - 000661160 _____ (Microsoft Corporation) C:\Windows\system32\GenValObj.exe
2018-07-06 23:12 - 2018-06-08 12:01 - 001046944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2018-07-06 23:12 - 2018-06-08 11:47 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2018-07-06 23:12 - 2018-06-08 11:46 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2018-07-06 23:12 - 2018-06-08 11:45 - 004392448 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2018-07-06 23:12 - 2018-06-08 11:45 - 001560576 _____ (Microsoft Corporation) C:\Windows\system32\msdt.exe
2018-07-06 23:12 - 2018-06-08 11:45 - 000808960 _____ C:\Windows\system32\MBR2GPT.EXE
2018-07-06 23:12 - 2018-06-08 11:44 - 001121792 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000625152 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000340992 _____ (Microsoft Corporation) C:\Windows\system32\AcGenral.dll
2018-07-06 23:12 - 2018-06-08 11:44 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\wlidcredprov.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 003640832 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2018-07-06 23:12 - 2018-06-08 11:43 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 001659904 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2018-07-06 23:12 - 2018-06-08 11:43 - 001543680 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2018-07-06 23:12 - 2018-06-08 11:42 - 003999232 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2018-07-06 23:12 - 2018-06-08 11:42 - 003653120 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2018-07-06 23:12 - 2018-06-08 11:42 - 000800256 _____ (Microsoft Corporation) C:\Windows\system32\pwcreator.exe
2018-07-06 23:12 - 2018-06-08 11:42 - 000503296 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 002019840 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2018-07-06 23:12 - 2018-06-08 11:41 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
2018-07-06 23:12 - 2018-06-08 11:41 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2018-07-06 23:12 - 2018-06-08 11:40 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2018-07-06 23:12 - 2018-06-08 10:07 - 000148896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mavinject.exe
2018-07-06 23:12 - 2018-06-08 10:04 - 001454024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2018-07-06 23:12 - 2018-06-08 09:58 - 000917408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2018-07-06 23:12 - 2018-06-08 09:50 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdt.exe
2018-07-06 23:12 - 2018-06-08 09:47 - 003492864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 002895872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2018-07-06 23:12 - 2018-06-08 09:47 - 001462784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 001032704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2018-07-06 23:12 - 2018-06-08 09:47 - 000231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcredprov.dll
2018-07-06 23:12 - 2018-06-08 09:46 - 003444224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2018-07-06 23:12 - 2018-06-08 09:46 - 000908288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2018-07-06 23:12 - 2018-06-08 09:45 - 002401280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcGenral.dll
2018-07-06 23:12 - 2018-06-08 09:06 - 000976384 _____ (Microsoft Corporation) C:\Windows\system32\Spectrum.exe
2018-07-06 23:12 - 2018-06-08 09:05 - 000944640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Mirage.Internal.dll
2018-07-06 23:12 - 2018-06-08 07:00 - 000658432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
2018-07-06 23:12 - 2018-06-08 03:38 - 005821544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2018-07-06 23:12 - 2018-06-08 03:37 - 002417840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2018-07-06 23:12 - 2018-06-08 03:35 - 001613200 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2018-07-06 23:12 - 2018-06-08 03:35 - 000613144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2018-07-06 23:12 - 2018-06-08 03:34 - 001299056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2018-07-06 23:12 - 2018-06-08 03:34 - 000748512 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2018-07-06 23:12 - 2018-06-08 03:31 - 003180176 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2018-07-06 23:12 - 2018-06-08 03:31 - 000029600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\uefi.sys
2018-07-06 23:12 - 2018-06-08 03:30 - 000705440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2018-07-06 23:12 - 2018-06-08 02:31 - 000226720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Ucx01000.sys
2018-07-06 23:12 - 2018-06-08 02:30 - 003296896 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 001363632 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 001063328 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2018-07-06 23:12 - 2018-06-08 02:30 - 000723360 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000722808 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000565152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2018-07-06 23:12 - 2018-06-08 02:30 - 000527264 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2018-07-06 23:12 - 2018-06-08 02:30 - 000194456 _____ (Microsoft Corporation) C:\Windows\system32\skci.dll
2018-07-06 23:12 - 2018-06-08 02:30 - 000137568 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 004970360 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 003283408 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 002590400 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2018-07-06 23:12 - 2018-06-08 02:29 - 002462272 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001792808 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001364184 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001190152 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 001026976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000678840 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000659096 _____ (Microsoft Corporation) C:\Windows\system32\StateRepository.Core.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000416144 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000375712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000313592 _____ (Microsoft Corporation) C:\Windows\system32\mfsensorgroup.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000266656 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000164768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2018-07-06 23:12 - 2018-06-08 02:29 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\vertdll.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000084288 _____ (Microsoft Corporation) C:\Windows\system32\LanguageOverlayUtil.dll
2018-07-06 23:12 - 2018-06-08 02:29 - 000057960 _____ (Microsoft Corporation) C:\Windows\system32\kernel.appcore.dll
2018-07-06 23:12 - 2018-06-08 02:12 - 000786176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 002479272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 002307336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2018-07-06 23:12 - 2018-06-08 02:10 - 001988072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000880152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000457152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2018-07-06 23:12 - 2018-06-08 02:10 - 000097176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 004469832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 002486992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 001584128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 001077504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000607648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000568720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryPS.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000553248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000064648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LanguageOverlayUtil.dll
2018-07-06 23:12 - 2018-06-08 02:09 - 000050208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel.appcore.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000906752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000038400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryCore.dll
2018-07-06 23:12 - 2018-06-08 02:03 - 000032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mskssrv.sys
2018-07-06 23:12 - 2018-06-08 02:02 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2018-07-06 23:12 - 2018-06-08 02:02 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\edpnotify.exe
2018-07-06 23:12 - 2018-06-08 02:02 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe
2018-07-06 23:12 - 2018-06-08 02:01 - 000342528 _____ (Microsoft Corporation) C:\Windows\system32\browserexport.exe
2018-07-06 23:12 - 2018-06-08 02:01 - 000295424 _____ (Microsoft Corporation) C:\Windows\system32\FSClient.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000294912 _____ (Microsoft Corporation) C:\Windows\system32\TDLMigration.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerCsp.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll
2018-07-06 23:12 - 2018-06-08 02:01 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-07-06 23:12 - 2018-06-08 02:00 - 001285120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000329216 _____ (Microsoft Corporation) C:\Windows\system32\credprovs.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2018-07-06 23:12 - 2018-06-08 02:00 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManagerClient.dll
2018-07-06 23:12 - 2018-06-08 02:00 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-07-06 23:12 - 2018-06-08 01:59 - 006032384 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 001318400 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000983040 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000673792 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000564736 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000456704 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2018-07-06 23:12 - 2018-06-08 01:59 - 000177152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryUpgrade.dll
2018-07-06 23:12 - 2018-06-08 01:59 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 003712512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 001676800 _____ (Microsoft Corporation) C:\Windows\system32\CoreShell.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 000781824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2018-07-06 23:12 - 2018-06-08 01:58 - 000239104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FSClient.dll
2018-07-06 23:12 - 2018-06-08 01:58 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe
2018-07-06 23:12 - 2018-06-08 01:57 - 003348992 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000483328 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2018-07-06 23:12 - 2018-06-08 01:57 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000150016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-07-06 23:12 - 2018-06-08 01:57 - 000038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 005307392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 003293696 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 002364928 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 001395200 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000916480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000908800 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:56 - 000871424 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000869376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000858112 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000715776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 000264704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovs.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 003441152 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 002248192 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 002061824 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001242112 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001192448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001171968 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 001160192 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000849408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000778752 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-07-06 23:12 - 2018-06-08 01:55 - 000776192 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000652800 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:55 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 002789376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001586176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001348096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 001128448 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000999936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000950272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000857088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:54 - 000842240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000729088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000646656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2018-07-06 23:12 - 2018-06-08 01:54 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAC3ENC.DLL
2018-07-06 23:12 - 2018-06-08 01:53 - 001675264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 001466368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000669696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000648192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-07-06 23:12 - 2018-06-08 01:53 - 000528384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2018-07-06 23:12 - 2018-06-06 11:57 - 003733320 _____ C:\Windows\system32\Windows.Mirage.dll
2018-07-06 23:12 - 2018-06-05 21:20 - 002841312 _____ C:\Windows\SysWOW64\Windows.Mirage.dll
2018-07-06 23:12 - 2018-06-01 16:24 - 000713376 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2018-07-06 23:12 - 2018-06-01 15:54 - 001825792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2018-07-06 23:12 - 2018-05-24 20:24 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-07-06 23:12 - 2018-05-20 12:45 - 000308408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-07-06 23:12 - 2018-05-20 12:42 - 001649760 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2018-07-06 23:12 - 2018-05-20 12:42 - 000759192 _____ (Microsoft Corporation) C:\Windows\system32\LicensingWinRT.dll
2018-07-06 23:12 - 2018-05-20 12:26 - 000486912 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll
2018-07-06 23:12 - 2018-05-20 12:23 - 004070400 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-07-06 23:12 - 2018-05-20 12:23 - 000947712 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2018-07-06 23:12 - 2018-05-20 12:23 - 000899072 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 001665024 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 001292288 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2018-07-06 23:12 - 2018-05-20 12:22 - 000941056 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll
2018-07-06 23:12 - 2018-05-20 12:22 - 000804352 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2018-07-06 23:12 - 2018-05-20 11:20 - 000022936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hvsicontainerservice.dll
2018-07-06 23:12 - 2018-05-20 11:15 - 000653208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicensingWinRT.dll
2018-07-06 23:12 - 2018-05-20 11:14 - 001490144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2018-07-06 23:12 - 2018-05-20 11:02 - 000461312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasplap.dll
2018-07-06 23:12 - 2018-05-20 11:00 - 000864768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2018-07-06 23:12 - 2018-05-20 10:59 - 000863232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2018-07-06 23:12 - 2018-05-20 10:59 - 000747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2018-07-06 23:12 - 2018-05-20 09:45 - 001271296 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
2018-07-06 23:12 - 2018-05-20 09:35 - 000677376 _____ (Microsoft Corporation) C:\Windows\system32\HeadTrackerStorage.dll
2018-07-06 23:12 - 2018-05-20 09:34 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\HoloShellRuntime.dll
2018-07-06 23:12 - 2018-05-20 07:54 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\HoloShellRuntime.dll
2018-07-06 23:12 - 2018-05-20 05:33 - 000105368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2018-07-06 23:12 - 2018-05-20 04:53 - 002178136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 001017088 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 001012408 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 000131232 _____ (Microsoft Corporation) C:\Windows\system32\rmclient.dll
2018-07-06 23:12 - 2018-05-20 04:53 - 000088472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys
2018-07-06 23:12 - 2018-05-20 04:52 - 000735560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2018-07-06 23:12 - 2018-05-20 04:52 - 000347704 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-07-06 23:12 - 2018-05-20 04:52 - 000130456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvsocket.sys
2018-07-06 23:12 - 2018-05-20 04:52 - 000089984 _____ (Microsoft Corporation) C:\Windows\system32\CompPkgSup.dll
2018-07-06 23:12 - 2018-05-20 04:34 - 000861096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll
2018-07-06 23:12 - 2018-05-20 04:33 - 001665920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2018-07-06 23:12 - 2018-05-20 04:33 - 000101288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rmclient.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 001034096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000560488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000286200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-07-06 23:12 - 2018-05-20 04:32 - 000077040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CompPkgSup.dll
2018-07-06 23:12 - 2018-05-20 04:31 - 001456640 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
2018-07-06 23:12 - 2018-05-20 04:28 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2018-07-06 23:12 - 2018-05-20 04:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\AppHostRegistrationVerifier.exe
2018-07-06 23:12 - 2018-05-20 04:28 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-07-06 23:12 - 2018-05-20 04:27 - 000344576 _____ (Microsoft Corporation) C:\Windows\system32\RasMediaManager.dll
2018-07-06 23:12 - 2018-05-20 04:27 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\ApiSetHost.AppExecutionAlias.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000356352 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe
2018-07-06 23:12 - 2018-05-20 04:26 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\TelephonyInteractiveUser.dll
2018-07-06 23:12 - 2018-05-20 04:26 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\MSHEIF.dll
2018-07-06 23:12 - 2018-05-20 04:25 - 000835584 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2018-07-06 23:12 - 2018-05-20 04:25 - 000384000 _____ (Microsoft Corporation) C:\Windows\system32\Phoneutil.dll
2018-07-06 23:12 - 2018-05-20 04:24 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-07-06 23:12 - 2018-05-20 04:24 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\DolbyMATEnc.dll
2018-07-06 23:12 - 2018-05-20 04:23 - 005951488 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2018-07-06 23:12 - 2018-05-20 04:23 - 000933376 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 001371136 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 001210880 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 000960512 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2018-07-06 23:12 - 2018-05-20 04:21 - 000783360 _____ (Microsoft Corporation) C:\Windows\system32\DolbyHrtfEnc.dll
2018-07-06 23:12 - 2018-05-20 04:17 - 002699776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-07-06 23:12 - 2018-05-20 04:16 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-07-06 23:12 - 2018-05-20 04:15 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2018-07-06 23:12 - 2018-05-20 04:15 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSHEIF.dll
2018-07-06 23:12 - 2018-05-20 04:14 - 000167936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtutil.exe
2018-07-06 23:12 - 2018-05-20 04:13 - 004929024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2018-07-06 23:12 - 2018-05-20 04:13 - 000317440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Phoneutil.dll
2018-07-06 23:12 - 2018-05-20 04:12 - 000860160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2018-07-06 23:12 - 2018-05-20 04:11 - 001036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2018-07-06 23:12 - 2018-05-20 04:11 - 001005568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2018-07-06 23:12 - 2018-05-20 01:26 - 000018716 _____ C:\Windows\system32\srms-apr.dat
2018-07-06 23:12 - 2018-05-18 10:08 - 000018716 _____ C:\Windows\SysWOW64\srms-apr.dat
2018-07-06 23:12 - 2018-04-28 07:25 - 000652184 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll
2018-07-06 23:12 - 2018-04-28 07:24 - 000749976 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll
2018-07-06 23:12 - 2018-04-28 07:23 - 000826776 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe
2018-07-06 23:12 - 2018-04-28 07:23 - 000399768 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 013570560 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 000171520 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-07-06 23:12 - 2018-04-28 07:03 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\SharedPCCSP.dll
2018-07-06 23:12 - 2018-04-28 07:01 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\MixedReality.Broker.dll
2018-07-06 23:12 - 2018-04-28 07:00 - 000695296 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2018-07-06 23:12 - 2018-04-28 06:58 - 001855488 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2018-07-06 23:12 - 2018-04-28 06:18 - 000150016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2018-07-06 23:12 - 2018-04-28 06:17 - 012500992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-07-06 23:12 - 2018-04-28 06:14 - 000581120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
2018-07-06 23:12 - 2018-04-28 06:13 - 001585664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2018-07-06 23:12 - 2018-04-28 06:12 - 001380864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2018-07-06 23:12 - 2018-04-28 03:58 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Analog.dll
2018-07-06 23:12 - 2018-04-27 21:31 - 000473496 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 001565592 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000788216 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000776880 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2018-07-06 23:12 - 2018-04-27 21:29 - 000494488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2018-07-06 23:12 - 2018-04-27 21:29 - 000382872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2018-07-06 23:12 - 2018-04-27 21:14 - 000434584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2018-07-06 23:12 - 2018-04-27 21:13 - 001426328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2018-07-06 23:12 - 2018-04-27 21:13 - 000665320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2018-07-06 23:12 - 2018-04-27 21:12 - 000606448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000585728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.th.dll
2018-07-06 23:12 - 2018-04-27 21:03 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.win81.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000613376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000474624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2018-07-06 23:12 - 2018-04-27 21:02 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-07-06 23:12 - 2018-04-27 21:01 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-07-06 23:12 - 2018-04-27 21:00 - 000143360 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-07-06 23:12 - 2018-04-27 20:59 - 000553984 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationExtensions.dll
2018-07-06 23:12 - 2018-04-27 20:58 - 003086336 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-07-06 23:12 - 2018-04-27 20:57 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-07-06 23:12 - 2018-04-27 20:55 - 001421312 _____ (Microsoft Corporation) C:\Windows\system32\rdpbase.dll
2018-07-06 23:12 - 2018-04-27 20:55 - 000543744 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-07-06 23:12 - 2018-04-27 20:54 - 000561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-07-06 23:12 - 2018-04-27 20:53 - 001235968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpbase.dll
2018-07-06 23:12 - 2018-04-27 20:53 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-07-06 23:12 - 2018-04-27 20:51 - 000524800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-07-06 23:12 - 2018-04-27 19:43 - 001953280 _____ C:\Windows\system32\rdpnano.dll
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_SurfaceDTXDriver_02_00_00.Wdf
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SurfacePenDriver_01011.Wdf
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\zh-sg
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\en-sg
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Windows\system32\en-au
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Program Files\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Program Files (x86)\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 ____D C:\Intel
2018-07-06 22:19 - 2018-07-06 22:19 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2018-07-06 22:18 - 2018-07-06 22:18 - 000003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-07-06 22:18 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-07-06 22:18 - 2017-10-19 12:20 - 005960824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 002587584 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 001766520 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000607352 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000449656 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000122816 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000082040 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-07-06 22:18 - 2017-10-12 20:11 - 007799931 _____ C:\Windows\system32\nvcoproc.bin
2018-07-06 22:18 - 2017-10-10 16:26 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-07-06 22:18 - 2017-09-13 16:20 - 000798008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2018-07-06 22:18 - 2017-09-13 16:20 - 000490296 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2018-07-06 22:18 - 2017-09-13 16:19 - 000927544 _____ C:\Windows\system32\vulkan-1.dll
2018-07-06 22:18 - 2017-09-13 16:19 - 000591160 _____ C:\Windows\system32\vulkaninfo.exe
2018-07-06 22:17 - 2018-07-08 09:14 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-06 22:17 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-07-06 22:17 - 2018-07-06 22:18 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-07-06 22:17 - 2018-07-06 22:17 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-07-06 22:17 - 2017-10-19 12:41 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2018-07-06 22:17 - 2017-09-24 14:31 - 000140280 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2018-07-06 22:12 - 2018-07-06 22:15 - 000000000 ____D C:\Windows\system32\MRT
2018-07-06 22:12 - 2018-07-06 22:12 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-07-06 22:12 - 2018-07-06 22:12 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-07-06 22:09 - 2018-07-06 22:09 - 000001464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2018-07-06 22:09 - 2018-07-06 22:09 - 000001452 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2018-07-06 22:09 - 2018-07-06 22:09 - 000000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2018-07-06 22:09 - 2018-07-06 22:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2018-07-06 22:09 - 2018-02-06 19:04 - 000032168 _____ (Safer-Networking Ltd.) C:\Windows\system32\sdnclean64.exe
2018-07-06 22:08 - 2018-07-07 20:43 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\TeaTimer (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\SDHelper (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\Misc. Support Library (Spybot - Search & Destroy)
2018-07-06 18:39 - 2018-07-06 18:39 - 000000000 ____D C:\Program Files (x86)\File Scanner Library (Spybot - Search & Destroy)
2018-07-06 18:38 - 2018-07-06 18:07 - 000548000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-07-06 18:28 - 2018-07-06 23:32 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2018-07-06 18:28 - 2018-07-06 22:06 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2018-07-06 18:08 - 2018-07-08 09:28 - 000000000 ___HD C:\Users\hometown\MicrosoftEdgeBackups
2018-07-06 18:08 - 2018-07-07 11:14 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-07-06 18:07 - 2018-07-06 18:27 - 000000000 ____D C:\ProgramData\RogueKiller
2018-07-06 18:07 - 2018-07-06 18:07 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-07-06 18:07 - 2018-07-06 18:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-07-06 18:07 - 2018-07-06 18:07 - 000000000 ____D C:\Program Files\RogueKiller
2018-07-06 16:17 - 2018-07-07 20:14 - 000000000 ____D C:\Users\hometown\AppData\Local\PlaceholderTileLogoFolder
2018-07-06 13:48 - 2018-07-06 14:07 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-07-06 06:04 - 2018-07-06 05:05 - 000000000 ____D C:\Windows\Panther
2018-07-06 05:26 - 2018-07-06 05:26 - 000000000 ____D C:\Users\hometown\AppData\Local\Comms
2018-07-06 05:11 - 2018-07-08 09:29 - 000000000 ____D C:\Users\hometown\AppData\Local\D3DSCache
2018-07-06 05:11 - 2018-07-07 02:38 - 000000000 ___RD C:\Users\hometown\OneDrive
2018-07-06 05:11 - 2018-07-06 05:11 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-07-06 05:10 - 2018-07-08 09:30 - 000793700 _____ C:\Windows\system32\PerfStringBackup.INI
2018-07-06 05:10 - 2018-07-07 00:32 - 000000000 ____D C:\Users\hometown\AppData\Local\MicrosoftEdge
2018-07-06 05:10 - 2018-07-06 05:10 - 000001417 _____ C:\Users\hometown\Desktop\Microsoft Edge.lnk
2018-07-06 05:09 - 2018-07-07 20:43 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-06 05:09 - 2018-07-07 20:43 - 000000000 ___RD C:\Users\hometown\3D Objects
2018-07-06 05:09 - 2018-07-07 20:12 - 000000000 ____D C:\Users\hometown\AppData\Local\Publishers
2018-07-06 05:09 - 2018-07-07 20:12 - 000000000 ____D C:\Users\hometown\AppData\Local\Packages
2018-07-06 05:09 - 2018-07-07 14:08 - 000000000 ____D C:\Users\hometown\AppData\Local\ConnectedDevicesPlatform
2018-07-06 05:09 - 2018-07-06 19:51 - 000000000 ____D C:\Users\hometown\AppData\Local\VirtualStore
2018-07-06 05:09 - 2018-07-06 18:08 - 000000000 ____D C:\Users\hometown
2018-07-06 05:09 - 2018-07-06 05:09 - 000000020 ___SH C:\Users\hometown\ntuser.ini
2018-07-06 05:09 - 2018-07-06 05:09 - 000000000 ____D C:\Users\hometown\AppData\Roaming\Adobe
2018-07-06 05:08 - 2018-07-06 05:08 - 000000000 ____D C:\Windows\CSC
2018-07-06 05:08 - 2018-07-06 05:08 - 000000000 ____D C:\ProgramData\USOShared
2018-07-06 05:08 - 2018-04-11 16:33 - 002752000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2018-07-06 05:06 - 2018-07-06 05:06 - 000000000 _SHDL C:\Documents and Settings
2018-07-06 05:04 - 2018-07-08 05:51 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-07-06 05:04 - 2018-07-07 20:43 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-07-06 05:04 - 2018-07-06 23:51 - 000233856 _____ C:\Windows\system32\FNTCACHE.DAT
2018-07-06 05:04 - 2018-07-06 22:20 - 000000000 ____D C:\Windows\system32\Drivers\wd
2018-07-06 05:04 - 2018-07-06 05:04 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2018-07-06 05:04 - 2018-07-06 05:04 - 000000000 ____D C:\Windows\ServiceProfiles
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-08 09:30 - 2018-04-11 16:36 - 000000000 ____D C:\Windows\INF
2018-07-08 09:26 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\zu-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\yo-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\xh-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\wo-SN
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\uz-Latn-UZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tn-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ti-ET
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tg-Cyrl-TJ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sr-Cyrl-RS
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sr-Cyrl-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sd-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\rw-RW
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\quc-Latn-GT
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\pa-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\nso-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ku-Arab-IQ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ig-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ha-Latn-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\chr-CHER-US
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ca-ES-valencia
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bs-Latn-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\az-Latn-AZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\zu-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\yo-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\xh-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\wo-SN
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\uz-Latn-UZ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tn-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ti-ET
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tg-Cyrl-TJ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sr-Cyrl-RS
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sr-Cyrl-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sd-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\rw-RW
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\quc-Latn-GT
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\pa-Arab-PK
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\nso-ZA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ku-Arab-IQ
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ig-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ha-Latn-NG
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\chr-CHER-US
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ca-ES-valencia
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bs-Latn-BA
2018-07-07 20:43 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\az-Latn-AZ
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\appraiser
2018-07-07 20:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\bcastdvr
2018-07-07 20:43 - 2018-04-11 14:04 - 000524288 _____ C:\Windows\system32\config\BBI
2018-07-07 20:40 - 2018-04-11 16:30 - 000000000 ____D C:\Windows\CbsTemp
2018-07-07 20:14 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\AppReadiness
2018-07-07 20:12 - 2018-04-11 16:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-07 18:25 - 2018-04-11 16:38 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-07-07 18:25 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-07-07 12:30 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\LiveKernelReports
2018-07-07 03:43 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\appcompat
2018-07-06 23:51 - 2018-04-12 02:37 - 000000000 ____D C:\Windows\Containers
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\vi-VN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ur-PK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ug-CN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tt-RU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\tk-TM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\te-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ta-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sw-KE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\sq-AL
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\si-LK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\quz-PE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\prs-AF
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\pa-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\or-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\nn-NO
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ne-NP
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mt-MT
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mr-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mn-MN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ml-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mk-MK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\mi-NZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\lo-LA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\lb-LU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ky-KG
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kok-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\km-KH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\kk-KZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ka-GE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\is-IS
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\id-ID
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\hy-AM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\gu-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\gd-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\ga-IE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\fil-PH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\fa-IR
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\cy-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\bn-BD
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\be-BY
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\as-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\am-ET
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\SysWOW64\af-ZA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\vi-VN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ur-PK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ug-CN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tt-RU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\tk-TM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\te-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sw-KE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\sq-AL
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\quz-PE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\prs-AF
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\pa-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\or-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\nn-NO
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ne-NP
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mt-MT
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mr-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mn-MN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ml-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mk-MK
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\mi-NZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\lo-LA
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\lb-LU
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ky-KG
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kok-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\km-KH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\kk-KZ
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ka-GE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\is-IS
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\id-ID
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\hy-AM
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\gu-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\gd-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\ga-IE
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\fil-PH
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\fa-IR
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\cy-GB
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bn-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\bn-BD
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\be-BY
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\as-IN
2018-07-06 23:51 - 2018-04-12 02:19 - 000000000 ____D C:\Windows\system32\af-ZA
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\TextInput
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\setup
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\ta-in
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\si-lk
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\setup
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\oobe
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\am-et
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\ShellExperiences
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\Provisioning
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-07-06 23:51 - 2018-04-11 16:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-07-06 23:51 - 2018-04-11 14:04 - 000000000 ____D C:\Windows\system32\Dism
2018-07-06 22:20 - 2018-04-11 16:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-07-06 22:19 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\es-MX
2018-07-06 22:19 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\en-GB
2018-07-06 22:17 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\Help
2018-07-06 19:47 - 2018-04-11 16:38 - 000000076 _____ C:\Windows\win.ini
2018-07-06 06:04 - 2018-04-11 16:38 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2018-07-06 05:09 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\spool
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\Windows\system32\FxsTmp
2018-07-06 05:08 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\USOPrivate
2018-07-06 05:04 - 2018-04-11 16:38 - 000000000 ___RD C:\Windows\PrintDialog
2018-07-06 05:04 - 2018-04-11 14:04 - 000032768 _____ C:\Windows\system32\config\ELAM
Some files in TEMP:
====================
2018-07-06 23:21 - 2018-07-06 23:21 - 000437120 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\BAP.exe
2018-07-06 18:07 - 2018-06-08 02:29 - 001946328 _____ (Microsoft Corporation) C:\Users\hometown\AppData\Local\Temp\dllnt_dump.dll
2018-07-06 23:20 - 2018-07-06 23:20 - 000592768 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\EKLXTWJ.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000580480 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\SEITI.exe
2018-07-06 23:20 - 2018-07-06 23:20 - 000494464 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\VL.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000461696 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\YBQJLPCWBJEEM.exe
2018-07-06 23:21 - 2018-07-06 23:21 - 000457600 _____ (Sysinternals - www.sysinternals.com (http://www.sysinternals.com)) C:\Users\hometown\AppData\Local\Temp\ZGMG.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-07-06 05:04
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by hometown (08-07-2018 10:26:42)
Running from C:\Users\hometown\Desktop
Windows 10 Pro Version 1803 17134.137 (X64) (2018-07-06 12:06:18)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2251815794-2661967540-3884843598-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2251815794-2661967540-3884843598-503 - Limited - Disabled)
Guest (S-1-5-21-2251815794-2661967540-3884843598-501 - Limited - Disabled)
hometown (S-1-5-21-2251815794-2661967540-3884843598-1001 - Administrator - Enabled) => C:\Users\hometown
WDAGUtilityAccount (S-1-5-21-2251815794-2661967540-3884843598-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: ESET Endpoint Antivirus 5.0 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 388.08 - NVIDIA Corporation) Hidden
ESET Endpoint Antivirus (HKLM\...\{3187B3B0-3620-4459-A983-4403FC481420}) (Version: 5.0.2214.4 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
NVIDIA Graphics Driver 388.08 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.08 - NVIDIA Corporation)
NVIDIA Update 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation)
RogueKiller version 12.12.25.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.25.0 - Adlice Software)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.22 - Tweaking.com)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\hometown\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-10-19] (NVIDIA Corporation)
ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Endpoint Antivirus\shellExt.dll [2013-02-14] (ESET)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {019CE806-0B74-40ED-ADD1-BE273A3DF3AB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-07] (Google Inc.)
Task: {07C89F96-897E-4E07-805C-8B5F92982B8E} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
Task: {1D9DF227-07F6-4130-A594-438A37B571AD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {281A2E0B-9528-47D7-8BED-F225577B499E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-10] (NVIDIA Corporation)
Task: {57362581-68DE-4AC5-896F-704CD50FB24E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {632BE4C5-384B-4425-9E20-48897F2194F7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-07] (Google Inc.)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {7C5D6F45-4540-49C5-AC37-FBD2C7298932} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {9C59F3C3-831D-4EB8-93AF-405EBA2301FE} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2017-05-02] (Tweaking.com)
Task: {A7BC178E-570C-4378-9ED0-CFB4EBE51C87} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2018-04-20] (Safer-Networking Ltd.)
Task: {C71348F5-0B6B-40C2-800F-17A705E8EF74} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-10] (NVIDIA Corporation)
Task: {EEA0CED9-3B52-4D03-9492-66CB27B9E490} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-10] (NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-04-11 16:34 - 2018-04-11 16:34 - 000253440 _____ () C:\Windows\System32\HeatCore.dll
2018-07-06 22:18 - 2017-10-19 12:20 - 000133568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 16:34 - 2018-04-11 16:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-07-06 23:12 - 2018-06-08 01:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-11-01 10:52 - 2017-11-01 10:52 - 000804744 _____ () C:\Windows\System32\SurfaceDTX.exe
2018-07-06 22:09 - 2018-02-05 16:57 - 000436016 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com (http://www.008k.com)
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com (http://www.00hq.com)
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com (http://www.0scan.com)
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com (http://www.1-2005-search.com)
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com (http://www.1-domains-registrations.com)
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com (http://www.1000gratisproben.com)
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com (http://www.1001namen.com)
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com (http://www.100sexlinks.com)
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com (http://www.10sek.com)
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info (http://www.123fporn.info)
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com (http://www.123moviedownload.com)
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com (http://www.123simsen.com)
There are 7939 more sites.
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\008k.com -> www.008k.com (http://www.008k.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\00hq.com -> www.00hq.com (http://www.00hq.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\0scan.com -> www.0scan.com (http://www.0scan.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1-2005-search.com -> www.1-2005-search.com (http://www.1-2005-search.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com (http://www.1-domains-registrations.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1000gratisproben.com -> www.1000gratisproben.com (http://www.1000gratisproben.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\1001namen.com -> www.1001namen.com (http://www.1001namen.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\100sexlinks.com -> www.100sexlinks.com (http://www.100sexlinks.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\10sek.com -> www.10sek.com (http://www.10sek.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123fporn.info -> www.123fporn.info (http://www.123fporn.info)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123moviedownload.com -> www.123moviedownload.com (http://www.123moviedownload.com)
IE restricted site: HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\...\123simsen.com -> www.123simsen.com (http://www.123simsen.com)
There are 7939 more sites.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-11 16:38 - 2018-07-08 09:27 - 000454646 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com (http://www.007guard.com)
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com (http://www.008k.com)
127.0.0.1 008k.com
127.0.0.1 www.00hq.com (http://www.00hq.com)
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com (http://www.032439.com)
127.0.0.1 032439.com
127.0.0.1 www.0scan.com (http://www.0scan.com)
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com (http://www.1000gratisproben.com)
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com (http://www.1001namen.com)
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com (http://www.100888290cs.com)
127.0.0.1 www.100sexlinks.com (http://www.100sexlinks.com)
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com (http://www.10sek.com)
127.0.0.1 www.1-2005-search.com (http://www.1-2005-search.com)
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info (http://www.123fporn.info)
127.0.0.1 www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com (http://www.123moviedownload.com)
There are 15605 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2251815794-2661967540-3884843598-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{35C00080-07FF-47BB-8747-520CB904D74A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/07/2018 08:43:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IntelAudioService.exe, version: 1.0.46.0, time stamp: 0x59afa72c
Faulting module name: KERNELBASE.dll, version: 10.0.17134.137, time stamp: 0x7745a173
Exception code: 0xe0434352
Fault offset: 0x000000000003a388
Faulting process id: 0xdd4
Faulting application start time: 0x01d4166dd89f001f
Faulting application path: C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: cd7aa138-04b7-4344-a380-7c276128dcc6
Faulting package full name:
Faulting package-relative application ID:
Error: (07/07/2018 08:43:35 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.DllNotFoundException
at IntelAudioService.Logger.AudioServiceLogger.SetLogMessageDelegate(LoggerDelegate)
at IntelAudioService.Logger.AudioServiceLogger..ctor()
at IntelAudioService.Logger.AudioServiceLogger.get_Instance()
at IntelAudioService.AudioService..ctor()
at IntelAudioService.Program.Main()
Error: (07/07/2018 08:14:22 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:14:20 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:14:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IntelAudioService.exe, version: 1.0.46.0, time stamp: 0x59afa72c
Faulting module name: KERNELBASE.dll, version: 10.0.17134.112, time stamp: 0xf2b2cb6c
Exception code: 0xe0434352
Fault offset: 0x000000000003a388
Faulting process id: 0xea4
Faulting application start time: 0x01d41669bbb93939
Faulting application path: C:\Windows\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 7943ae0d-afe4-40c9-8103-2353cb6a9533
Faulting package full name:
Faulting package-relative application ID:
Error: (07/07/2018 08:14:07 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.DllNotFoundException
at IntelAudioService.Logger.AudioServiceLogger.SetLogMessageDelegate(LoggerDelegate)
at IntelAudioService.Logger.AudioServiceLogger..ctor()
at IntelAudioService.Logger.AudioServiceLogger.get_Instance()
at IntelAudioService.AudioService..ctor()
at IntelAudioService.Program.Main()
Error: (07/07/2018 08:09:31 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(15ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (07/07/2018 08:09:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-VTV5VMP$ via https://IFX-KeyId-40b8682b8d18450a2b06849d9b5cd96f4cddf4be.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (07/08/2018 10:23:42 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:27:43 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/08/2018 09:26:02 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
Error: (07/07/2018 08:50:22 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-VTV5VMP)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user DESKTOP-VTV5VMP\hometown SID (S-1-5-21-2251815794-2661967540-3884843598-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/07/2018 08:43:47 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/07/2018 08:43:47 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Windows Defender:
===================================
Date: 2018-07-06 19:58:52.993
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.643.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2018-07-06 17:58:47.774
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.773
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.773
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2018-07-06 17:58:47.678
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.263.48.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14600.4
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-6600U CPU @ 2.60GHz
Percentage of memory in use: 21%
Total physical RAM: 16309.29 MB
Available physical RAM: 12804.39 MB
Total Virtual: 19253.29 MB
Available Virtual: 12886.38 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:476.34 GB) (Free:444.58 GB) NTFS
\\?\Volume{9e7df45b-cb0b-47d8-912e-9ef5e4e8a6dc}\ (Recovery) (Fixed) (Total:0.49 GB) (Free:0.13 GB) NTFS
\\?\Volume{432b50d5-0a2c-444f-b184-77bfde5d7507}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
Run date: 2018-07-08 11:03:07
-----------------------------
11:03:07.636 OS Version: Windows x64 6.2.9200
11:03:07.636 Number of processors: 4 586 0x4E03
11:03:07.636 ComputerName: DESKTOP-VTV5VMP UserName: hometown
11:03:07.904 Initialize success
11:03:07.920 VM: initialized successfully
11:03:07.920 VM: Intel CPU supported
11:03:11.984 VM: not used
11:03:42.722 AVAST engine defs: 17030301
11:03:48.939 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003a
11:03:48.939 Disk 0 Vendor: SAMSUNG_MZFLV512HCJH-000MV BXV75M0Q Size: 488386MB BusType: 17
11:03:48.954 Disk 0 MBR read successfully
11:03:48.954 Disk 0 MBR scan
11:03:48.970 Disk 0 unknown MBR code
11:03:48.970 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
11:03:48.970 Disk 0 scanning C:\Windows\system32\drivers
11:03:48.986 Service scanning
11:04:12.856 Modules scanning
11:04:13.122 AVAST engine scan C:\Windows
11:04:13.122 AVAST engine scan C:\Windows\system32
11:04:13.137 AVAST engine scan C:\Windows\system32\drivers
11:04:13.137 AVAST engine scan C:\Users\hometown
11:04:13.137 AVAST engine scan C:\ProgramData
11:04:13.153 Scan finished successfully
11:05:21.612 Disk 0 MBR has been saved successfully to "C:\Users\hometown\Desktop\MBR.dat"
11:05:21.628 The log file has been saved successfully to "C:\Users\hometown\Desktop\aswMBR.txt"
I tried to run this with the virtulization and it would crash I also could not run it with trace disk io calls.
I have tried malwarebyted, esat, spybot, tweaker.com and several others in my futile attempt to fix this problem. I am sure it is on my network and has spread to two other computers.